QID 997896
Date Published: 2024-04-02
QID 997896: GO (Go) Security Update for github.com/hashicorp/nomad (GHSA-v5fm-hr72-27hx)
A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability, CVE-2023-3300, affects Nomad since 0.11 and was fixed in 1.6.0, 1.5.7, and 1.4.11.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-v5fm-hr72-27hx for updates and patch information.
Vendor References
- GHSA-v5fm-hr72-27hx -
github.com/advisories/GHSA-v5fm-hr72-27hx
CVEs related to QID 997896
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v5fm-hr72-27hx | github.com/hashicorp/nomad |
|