PT-2022-24518 · Hashicorp · Nomad+1

CVE-2022-3867

·

Published

2022-11-10

·

Updated

2024-08-21

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Nomad and Nomad Enterprise versions 1.4.0 through 1.4.1
Description The issue affects event stream subscribers using a token with TTL, allowing them to receive updates until token garbage is collected.
Recommendations For versions 1.4.0 through 1.4.1, update to version 1.4.2 to resolve the issue.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3867
GHSA-9FMC-5FQ4-5JWH
GO-2022-1106

Affected Products

Nomad
Nomad Enterprise