Beveiligingsadvies

CVE-2025-1296

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-03-10 18:02:21
Laatst bijgewerkt 2025-03-11 20:18:55
Toegewezen door HashiCorp
CVSS-score 6.5
Status PUBLISHED

Beschrijving

Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19.