{"id":"GHSA-9jfx-84v9-2rr2","summary":"Nomad Caller ACL Token’s Secret ID is Exposed to Sentinel","details":"A vulnerability was identified in Nomad such that the API caller’s ACL token secret ID is exposed to Sentinel policies. This vulnerability, CVE-2023-3299, affects Nomad from 1.2.11 up to 1.5.6, and 1.4.10 and was fixed in 1.6.0, 1.5.7, and 1.4.11.","aliases":["CVE-2023-3299","GO-2024-2669"],"modified":"2024-09-26T21:43:03Z","published":"2023-07-20T00:30:24Z","database_specific":{"github_reviewed_at":"2024-04-01T18:30:58Z","nvd_published_at":"2023-07-20T00:15:10Z","cwe_ids":["CWE-201","CWE-668"],"severity":"LOW","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3299"},{"type":"WEB","url":"https://github.com/hashicorp/nomad/issues/17907"},{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2023-21-nomad-caller-acl-tokens-secret-id-is-exposed-to-sentinel/56271"},{"type":"PACKAGE","url":"https://github.com/hashicorp/nomad"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2024-2669"}],"affected":[{"package":{"name":"github.com/hashicorp/nomad","ecosystem":"Go","purl":"pkg:golang/github.com/hashicorp/nomad"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.2.11"},{"fixed":"1.4.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-9jfx-84v9-2rr2/GHSA-9jfx-84v9-2rr2.json"}},{"package":{"name":"github.com/hashicorp/nomad","ecosystem":"Go","purl":"pkg:golang/github.com/hashicorp/nomad"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.5.0"},{"fixed":"1.5.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-9jfx-84v9-2rr2/GHSA-9jfx-84v9-2rr2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N"}]}