Vulnerability Description
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Nomad | 1.4.0 |
Related Weaknesses (CWE)
References
- https://discuss.hashicorp.com/t/hcsec-2022-25-nomad-s-workload-identity-token-caVendor Advisory
- https://discuss.hashicorp.com/t/hcsec-2022-25-nomad-s-workload-identity-token-caVendor Advisory
FAQ
What is CVE-2022-3866?
CVE-2022-3866 is a vulnerability with a CVSS score of 5.0 (MEDIUM). HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.
How severe is CVE-2022-3866?
CVE-2022-3866 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3866?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Nomad.