Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39779
HistoryMar 15, 2023 - 3:29 a.m.

Information Disclosure

2023-03-1503:29:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
github
nomad
acl
vulnerability
exposed
sensitive information
authenticated
remote attackers
bypassed
workload

EPSS

0.001

Percentile

25.7%

github.com/hashicorp/nomad is vulnerable to Information Disclosure. The vulnerability is due to the ACL system failing to block access to sensitive information from remote authenticated attackers because the deny ACL capability could be bypassed exposing the workloadโ€™s own variables.

EPSS

0.001

Percentile

25.7%