GHSA-f8r8-h93m-mj77
GitHub Security Advisory
HashiCorp Nomad vulnerable to unauthenticated client agent HTTP request privilege escalation
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.
Affected Packages
Go
github.com/hashicorp/nomad
Affected versions:
1.5.0
(fixed in 1.5.3)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: July 6, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.