{"id":"GHSA-9fmc-5fq4-5jwh","summary":"HashiCorp Nomad vulnerable to Insufficient Session Expiration","details":"HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.","aliases":["CVE-2022-3867","GO-2022-1106"],"modified":"2024-08-21T16:28:44.881445Z","published":"2022-11-10T12:01:03Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2022-11-10T23:51:03Z","nvd_published_at":"2022-11-10T06:15:00Z","cwe_ids":["CWE-613"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-3867"},{"type":"WEB","url":"https://github.com/hashicorp/nomad/commit/dd6a4634a9652197fe4182e830f9a737d0ae1216"},{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2022-26-nomad-s-event-stream-subscriber-using-acl-token-with-ttl-receive-updates-until-garbage-collected/46168"},{"type":"PACKAGE","url":"https://github.com/hashicorp/nomad"}],"affected":[{"package":{"name":"github.com/hashicorp/nomad","ecosystem":"Go","purl":"pkg:golang/github.com/hashicorp/nomad"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.4.0"},{"fixed":"1.4.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-9fmc-5fq4-5jwh/GHSA-9fmc-5fq4-5jwh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N"}]}