CVE Vulnerabilities

CVE-2023-3300

Incorrect Privilege Assignment

Published: Jul 20, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. Fixed in 1.6.0, 1.5.7, and 1.4.1.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
NomadHashicorp0.11.0 (including)1.4.1 (including)
NomadHashicorp1.5.0 (including)1.5.6 (including)
NomadUbuntubionic*
NomadUbuntufocal*
NomadUbuntutrusty*
NomadUbuntuxenial*

Potential Mitigations

References