Nomad ACLs Can Not Deny Access to Workload's Own Variables
CVE-2023-1296
2.7LOW
What is CVE-2023-1296?
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and 1.5.1.
Affected Version(s)
Nomad 64 bit 1.5.0
Nomad 64 bit 1.4.0 < 1.4.6
Nomad Enterprise 64 bit 1.5.0