CVE Vulnerabilities

CVE-2025-1296

Insertion of Sensitive Information into Log File

Published: Mar 10, 2025 | Modified: Dec 18, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
NomadHashicorp1.0.0 (including)1.7.19 (excluding)
NomadHashicorp1.0.0 (including)1.9.7 (excluding)
NomadHashicorp1.8.0 (including)1.8.11 (excluding)
NomadHashicorp1.9.0 (including)1.9.7 (excluding)
NomadUbuntufocal*

Potential Mitigations

References