Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.
2025-02-12T19:15:09.687
2025-12-15T21:07:54.137
Analyzed
CVSSv3.1: 7.1 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | hashicorp | nomad | < 1.7.18 | Yes |
| Application | hashicorp | nomad | < 1.9.6 | Yes |
| Application | hashicorp | nomad | < 1.8.10 | Yes |
| Application | hashicorp | nomad | < 1.9.6 | Yes |