{"id":"GHSA-7wg4-8m5p-hrfg","summary":"HashiCorp Nomad vulnerable to non-sensitive metadata exposure","details":"HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under `nomad/` that belong to other jobs in the same namespace. Fixed in 1.4.2.","aliases":["CVE-2022-3866","GO-2022-1105"],"modified":"2024-08-21T16:28:38.410432Z","published":"2022-11-10T12:01:03Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-11-10T23:51:44Z","nvd_published_at":"2022-11-10T06:15:00Z","cwe_ids":["CWE-668"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-3866"},{"type":"WEB","url":"https://github.com/hashicorp/nomad/commit/3b24f26603e2b116ba324101afa8a7e3a7a769a5"},{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2022-25-nomad-s-workload-identity-token-can-list-non-sensitive-metadata-for-nomad-paths/46167"},{"type":"PACKAGE","url":"https://github.com/hashicorp/nomad"}],"affected":[{"package":{"name":"github.com/hashicorp/nomad","ecosystem":"Go","purl":"pkg:golang/github.com/hashicorp/nomad"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.4.0"},{"fixed":"1.4.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-7wg4-8m5p-hrfg/GHSA-7wg4-8m5p-hrfg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"}]}