Loading HuntDB...

GHSA-9fmc-5fq4-5jwh

GitHub Security Advisory

HashiCorp Nomad vulnerable to Insufficient Session Expiration

✓ GitHub Reviewed LOW Has CVE

Advisory Details

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.

Affected Packages

Go github.com/hashicorp/nomad
Affected versions: 1.4.0 (fixed in 1.4.2)

Related CVEs

Key Information

GHSA ID
GHSA-9fmc-5fq4-5jwh
Published
November 10, 2022 12:01 PM
Last Modified
November 10, 2022 11:51 PM
CVSS Score
2.5 /10
Primary Ecosystem
Go
Primary Package
github.com/hashicorp/nomad
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.