Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39780
HistoryMar 15, 2023 - 3:49 a.m.

Privilege Escalation

2023-03-1503:49:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
vulnerability
remote attacker
acl permission
management-level privileges
workload identity
task api
acl policies

0.001 Low

EPSS

Percentile

32.1%

github.com/hashicorp/nomad is vulnerable to Privilege Escalation. A remote attacker with the submit-job ACL permission is able to escalate to management-level privileges using the workload identity and task API by submitting a job without ACL policies.

0.001 Low

EPSS

Percentile

32.1%