CVE-2023-3300
20.07.2023, 00:15
HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. Fixed in 1.6.0, 1.5.7, and 1.4.1.Enginsight
Vendor | Product | Version |
---|---|---|
hashicorp | nomad | 0.11.0 ≤ 𝑥 ≤ 1.4.1 |
hashicorp | nomad | 0.11.0 ≤ 𝑥 ≤ 1.4.1 |
hashicorp | nomad | 1.5.0 ≤ 𝑥 ≤ 1.5.6 |
hashicorp | nomad | 1.5.0 ≤ 𝑥 ≤ 1.5.6 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
- CWE-266 - Incorrect Privilege AssignmentA product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
- CWE-862 - Missing AuthorizationThe software does not perform an authorization check when an actor attempts to access a resource or perform an action.