Vulnerability Report: GO-2024-2670
- CVE-2023-3072, GHSA-rpvr-38xv-xvxq
- Affects: github.com/hashicorp/nomad
- Published: Apr 04, 2024
- Modified: May 20, 2024
An ACL policy using a block without label can be applied to unexpected resources in Nomad, a distributed, highly available scheduler designed for effortless operations and management of applications.
Affected Modules
-
PathGo Versions
-
from v0.7.0 before v1.4.11, from v1.5.0 before v1.5.6
Aliases
References
- https://discuss.hashicorp.com/t/hcsec-2023-20-nomad-acl-policies-without-label-are-applied-to-unexpected-resources/56270
- https://vuln.go.dev/ID/GO-2024-2670.json
Credits
- anonymous4ACL24
Feedback
See anything missing or incorrect?
Suggest an edit to this report.