Loading HuntDB...

GHSA-f8r8-h93m-mj77

GitHub Security Advisory

HashiCorp Nomad vulnerable to unauthenticated client agent HTTP request privilege escalation

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.

Affected Packages

Go github.com/hashicorp/nomad
Affected versions: 1.5.0 (fixed in 1.5.3)

Related CVEs

Key Information

GHSA ID
GHSA-f8r8-h93m-mj77
Published
April 5, 2023 9:30 PM
Last Modified
April 6, 2023 4:59 PM
CVSS Score
7.5 /10
Primary Ecosystem
Go
Primary Package
github.com/hashicorp/nomad
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.