QID 981025
QID 981025: Go (go) Security Update for github.com/hashicorp/nomad (GHSA-c8x3-rg72-fwwg)
HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-c8x3-rg72-fwwg for updates pertaining to this vulnerability.
Vendor References
- GHSA-c8x3-rg72-fwwg -
github.com/advisories/GHSA-c8x3-rg72-fwwg
CVEs related to QID 981025
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c8x3-rg72-fwwg | github.com/hashicorp/nomad |
|