A vulnerability was identified in Nomad and Nomad Enterprise (“Nomad”) such that a deny ACL capability could not be applied to a workload’s own variables. If included, the Nomad ACL system will silently fail to block access. This vulnerability, CVE-2023-1296, was fixed in Nomad 1.4.6 and 1.5.1.
{
"github_reviewed_at": "2023-07-06T21:54:20Z",
"severity": "MODERATE",
"github_reviewed": true,
"cwe_ids": [],
"nvd_published_at": "2023-03-14T15:15:00Z"
}