Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19. | |
| Title | Nomad Exposes Sensitive Workload Identity and Client Secret Token in Audit Logs | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published: 2025-03-10T18:02:21.579Z
Updated: 2025-03-11T20:18:55.186Z
Reserved: 2025-02-14T01:10:26.947Z
Link: CVE-2025-1296
Updated: 2025-03-11T20:18:50.353Z
Status : Received
Published: 2025-03-10T18:15:30.237
Modified: 2025-03-10T18:15:30.237
Link: CVE-2025-1296
No data.