{"id":"GHSA-v5fm-hr72-27hx","summary":"Nomad Search API Leaks Information About CSI Plugins","details":"A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability, CVE-2023-3300, affects Nomad since 0.11 and was fixed in 1.6.0, 1.5.7, and 1.4.11.","aliases":["CVE-2023-3300","GO-2024-2671"],"modified":"2024-04-05T15:34:59Z","published":"2023-07-20T00:30:25Z","database_specific":{"github_reviewed_at":"2024-04-01T19:17:38Z","nvd_published_at":"2023-07-20T00:15:10Z","cwe_ids":["CWE-266","CWE-862"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3300"},{"type":"WEB","url":"https://github.com/hashicorp/nomad/commit/a8789d3872bbf1b1f420f28b0f7ad8532a41d5e3"},{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2023-22-nomad-search-api-leaks-information-about-csi-plugins/56272"},{"type":"PACKAGE","url":"https://github.com/hashicorp/nomad"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2024-2671"}],"affected":[{"package":{"name":"github.com/hashicorp/nomad","ecosystem":"Go","purl":"pkg:golang/github.com/hashicorp/nomad"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.11.0"},{"fixed":"1.4.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-v5fm-hr72-27hx/GHSA-v5fm-hr72-27hx.json"}},{"package":{"name":"github.com/hashicorp/nomad","ecosystem":"Go","purl":"pkg:golang/github.com/hashicorp/nomad"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.5.0"},{"fixed":"1.5.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-v5fm-hr72-27hx/GHSA-v5fm-hr72-27hx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}