CVE-2023-1782

EUVD-2023-1283
HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.9 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
HashiCorpCNA
10 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
Affected Products (NVD)
VendorProductVersion
hashicorpnomad
1.5.0 ≤
𝑥
≤ 1.5.2
hashicorpnomad
1.5.0 ≤
𝑥
≤ 1.5.2
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nomad
bionic
needs-triage
focal
needs-triage
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
ignored