HashiCorp Nomad是美国HashiCorp公司的一个简单灵活的调度器和编排器。用于在本地和云中大规模管理容器和非容器化应用程序。 HashiCorp Nomad 和 Nomad Enterpris存在安全漏洞,该漏洞源于API调用方的ACL令牌ID会暴露给Sentinel策略。受影响的产品和版本:HashiCorp Nomad 和 Nomad Enterprise 1.2.11至1.5.6版本,1.4.10版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashiCorp | Nomad Enterprise | 1.2.11 ~ 1.4.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-3300 | 5.3 MEDIUM | Nomad Search API Leaks Information About CSI Plugins |
| CVE-2023-3072 | 4.1 MEDIUM | Nomad ACL Policies without Label are Applied to Unexpected Resources |
No comments yet