CVE-2025-3744
13.05.2025, 19:15
Nomad Enterprise (Nomad) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.Enginsight
Vendor | Product | Version |
---|---|---|
hashicorp | nomad | 𝑥 < 1.8.13 |
hashicorp | nomad | 1.9.0 ≤ 𝑥 < 1.9.9 |
hashicorp | nomad | 1.10.0 |
hashicorp | nomad | 1.10.0:beta1 |
hashicorp | nomad | 1.10.0:rc1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration