Show filters
48 Total Results
Displaying 11-20 of 48
Sort by:
Attacker Value
Unknown

CVE-2024-23588

Disclosure Date: July 05, 2024 (last updated July 09, 2024)
HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability.
Attacker Value
Unknown

CVE-2024-1329

Disclosure Date: February 08, 2024 (last updated September 26, 2024)
HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. This vulnerability, CVE-2024-1329, is fixed in Nomad 1.7.4, 1.6.7, and 1.5.14.
Attacker Value
Unknown

CVE-2023-23342

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
If certain local files are manipulated in a certain manner, the validation to use the cryptographic keys can be circumvented. 
Attacker Value
Unknown

CVE-2023-3300

Disclosure Date: July 20, 2023 (last updated October 08, 2023)
HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. Fixed in 1.6.0, 1.5.7, and 1.4.1.
Attacker Value
Unknown

CVE-2023-3299

Disclosure Date: July 20, 2023 (last updated September 26, 2024)
HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.
Attacker Value
Unknown

CVE-2023-3072

Disclosure Date: July 20, 2023 (last updated October 08, 2023)
HashiCorp Nomad and Nomad Enterprise 0.7.0 up to 1.5.6 and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.
Attacker Value
Unknown

CVE-2023-1782

Disclosure Date: April 05, 2023 (last updated October 08, 2023)
HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.
Attacker Value
Unknown

CVE-2023-1299

Disclosure Date: March 14, 2023 (last updated October 08, 2023)
HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fixed in 1.5.1.
Attacker Value
Unknown

CVE-2023-1296

Disclosure Date: March 14, 2023 (last updated October 08, 2023)
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and 1.5.1.
Attacker Value
Unknown

CVE-2022-34910

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a local database to store data and accounts. However, the password is stored in cleartext. Therefore, an attacker can retrieve the passwords of other users that used the same device.