PT-2023-24131 · Hashicorp+1 · Nomad Enterprise+2

CVE-2023-3300

·

Publicado

2023-07-19

·

Atualizado

2025-05-26

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Nomad and Nomad Enterprise versions 0.11.0 through 1.5.6 HashiCorp Nomad and Nomad Enterprise version 1.4.1
Description A vulnerability in the HTTP search API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy.
Recommendations For versions 0.11.0 through 1.5.6, update to version 1.5.7 or later to resolve the issue. For version 1.4.1, update to version 1.4.11 or later to resolve the issue.

Exploit

Correção

Missing Authorization

Incorrect Privilege Assignment

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-06167
CVE-2023-3300
GHSA-V5FM-HR72-27HX
GO-2024-2671

Produtos afetados

Hashicorp Nomad
Nomad Enterprise
Red Os