You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Bulletin ID: HCSEC-2022-25
Bulletin Title: Nomad Workload Identity Token Can List Non-sensitive Metadata for Paths Under nomad/
Publication Date: October 27, 2022
Affected Products / Versions: Nomad and Nomad Enterprise 1.4.0 up to 1.4.1; fixed in 1.4.2.
Summary:
A vulnerability was identified in Nomad and Nomad Enterprise (“Nomad”) such that a workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace.This vulnerability, with CVE assignment pending, was fixed in Nomad 1.4.2.
Background:
Nomad’s workload identity is a JWT signed by the leader's keyring that is currently only used for template access to Variables, and not exposed outside of Nomad.
Details:
During internal testing it was observed that a workload identity token can be used to list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. The metadata consists only of the path (job/group/task name) and create/modify timestamps.
This behavior may be used by a malicious operator or third party with authenticated access to access non-sensitive information which may provide context they otherwise might not have. Nomad’s authorization logic has been modified to prevent this potential abuse scenario.
Remediation:
Customers should evaluate the risk associated with this issue and consider upgrading to Nomad 1.4.2, or newer.
See Nomad’s Upgrading for general guidance on this process.
Acknowledgement:
This issue was identified internally by the Nomad engineering team.
Additional content required for disclosure:
CVE Description:
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.
I'm going to lock this issue because it has been closed for 120 days ⏳. This helps our maintainers find and focus on the active issues.
If you have found a problem that seems similar to this, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.
Bulletin ID: HCSEC-2022-25
Bulletin Title: Nomad Workload Identity Token Can List Non-sensitive Metadata for Paths Under nomad/
Publication Date: October 27, 2022
Affected Products / Versions: Nomad and Nomad Enterprise 1.4.0 up to 1.4.1; fixed in 1.4.2.
Summary:
A vulnerability was identified in Nomad and Nomad Enterprise (“Nomad”) such that a workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace.This vulnerability, with CVE assignment pending, was fixed in Nomad 1.4.2.
Background:
Nomad’s workload identity is a JWT signed by the leader's keyring that is currently only used for template access to Variables, and not exposed outside of Nomad.
Details:
During internal testing it was observed that a workload identity token can be used to list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. The metadata consists only of the path (job/group/task name) and create/modify timestamps.
This behavior may be used by a malicious operator or third party with authenticated access to access non-sensitive information which may provide context they otherwise might not have. Nomad’s authorization logic has been modified to prevent this potential abuse scenario.
Remediation:
Customers should evaluate the risk associated with this issue and consider upgrading to Nomad 1.4.2, or newer.
See Nomad’s Upgrading for general guidance on this process.
Acknowledgement:
This issue was identified internally by the Nomad engineering team.
Additional content required for disclosure:
CVE Description:
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.
CHANGELOG Entry:
https://github.com/hashicorp/nomad/blob/v1.4.2/CHANGELOG.md#142-october-26-2022
The text was updated successfully, but these errors were encountered: