QID 982570
QID 982570: Go (go) Security Update for github.com/hashicorp/nomad (GHSA-cj2h-ww36-v932)
HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cj2h-ww36-v932 for updates pertaining to this vulnerability.
Vendor References
- GHSA-cj2h-ww36-v932 -
github.com/advisories/GHSA-cj2h-ww36-v932
CVEs related to QID 982570
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cj2h-ww36-v932 | github.com/hashicorp/nomad |
|