CVE Vulnerabilities

CVE-2024-12678

Incorrect Privilege Assignment

Published: Dec 20, 2024 | Modified: Dec 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu
MEDIUM

Nomad Community and Nomad Enterprise (Nomad) allocations are vulnerable to privilege escalation within a namespace through unredacted workload identity tokens. This vulnerability, identified as CVE-2024-12678, is fixed in Nomad Community Edition 1.9.4 and Nomad Enterprise 1.9.4, 1.8.8, and 1.7.16.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Nomad Hashicorp 1.4.0 (including) 1.7.16 (excluding)
Nomad Hashicorp 1.4.0 (including) 1.9.4 (excluding)
Nomad Hashicorp 1.8.0 (including) 1.8.8 (excluding)
Nomad Hashicorp 1.9.0 (including) 1.9.4 (excluding)
Nomad Ubuntu focal *

Potential Mitigations

References