← Back to browse · API

CVE-2023-1782

Severity
CRITICAL
CVSS
10.0
EPSS
0.00759
Risk score
40.27
CISA KEV
No
PoC
No
Published
2023-04-05
Modified
2025-02-10
First seen
2026-08-07
Aliases
EUVD-2023-1283, GHSA-F8R8-H93M-MJ77
Products
Hashicorp:Nomad 1.5.0 <1.5.3, Hashicorp:Nomad Enterprise 1.5.0 <1.5.3
Sources
euvd EUVD-2023-1283

Description

HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.

References