Back to overview

CVE-2023-1782

CRITICAL
10.0
CVSS 3.1
Description
HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.

Metadata

CVE ID
CVE-2023-1782
State
PUBLISHED
Assigner
HashiCorp
Reserved
2023-03-31 14:50 UTC
Published
2023-04-05 19:10 UTC
Last updated
2025-02-10 16:27 UTC
Primary CWE
CWE-862
CWE-862 Missing Authorization
Vendor / Product
HashiCorp / Nomad
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (2)
VendorProductPlatformVersions
HashiCorp Nomad 64 bit,32 bit,x86,ARM,MacOS,Windows,Linux 1.5.0 < 1.5.3
HashiCorp Nomad Enterprise 64 bit,32 bit,x86,ARM,MacOS,Windows,Linux 1.5.0 < 1.5.3
Weakness (CWE)
CWESourceDescription
CWE-862 cna CWE-862 Missing Authorization
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview