CVE-2023-3299
20.07.2023, 00:15
HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.Enginsight
Vendor | Product | Version |
---|---|---|
hashicorp | nomad | 1.2.11 ≤ 𝑥 ≤ 1.4.10 |
hashicorp | nomad | 1.2.11 ≤ 𝑥 ≤ 1.4.10 |
hashicorp | nomad | 1.5.0 ≤ 𝑥 ≤ 1.5.6 |
hashicorp | nomad | 1.5.0 ≤ 𝑥 ≤ 1.5.6 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
- CWE-201 - Insertion of Sensitive Information Into Sent DataThe code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
- CWE-668 - Exposure of Resource to Wrong SphereThe product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.