Vulnerabilities > CVE-2022-3867 - Insufficient Session Expiration vulnerability in Hashicorp Nomad 1.4.0/1.4.1
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |