Low severity3.4NVD Advisory· Published Jul 20, 2023· Updated Jun 17, 2026
CVE-2023-3299
CVE-2023-3299
Description
HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/hashicorp/nomadGo | >= 1.2.11, < 1.4.11 | 1.4.11 |
github.com/hashicorp/nomadGo | >= 1.5.0, < 1.5.7 | 1.5.7 |
Affected products
4- Range: 1.2.11
Patches
Vulnerability mechanics
References
5- discuss.hashicorp.com/t/hcsec-2023-21-nomad-caller-acl-tokens-secret-id-is-exposed-to-sentinel/56271nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-9jfx-84v9-2rr2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-3299ghsaADVISORY
- github.com/hashicorp/nomad/issues/17907ghsaWEB
- pkg.go.dev/vuln/GO-2024-2669ghsaWEB
News mentions
0No linked articles in our index yet.