Vulnerabilities > CVE-2023-3072 - Missing Authorization vulnerability in Hashicorp Nomad

047910
CVSS 3.8 - LOW
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
hashicorp
CWE-862

Summary

HashiCorp Nomad and Nomad Enterprise 0.7.0 up to 1.5.6 and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.

Vulnerable Configurations

Part Description Count
Application
Hashicorp
178

Common Weakness Enumeration (CWE)