CVE-2023-1782
Published Apr 5, 2023
Last updated 2 years ago
Overview
- Description
- HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.
- Source
- security@hashicorp.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*", "vulnerable": true, "matchCriteriaId": "CF6C682F-831D-4514-9D9A-F23081D65DEB", "versionEndIncluding": "1.5.2", "versionStartIncluding": "1.5.0" }, { "criteria": "cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "90D15FCA-79C3-49CF-9816-6862E9A5A7A8", "versionEndIncluding": "1.5.2", "versionStartIncluding": "1.5.0" } ], "operator": "OR" } ] } ]