blob: 4101ca4e1b0a032a08d7f39678183c024f8cd1a7 [file] [log] [blame]
id: GO-2025-3758
modules:
- module: github.com/hashicorp/nomad
versions:
- fixed: 1.10.2
vulnerable_at: 1.10.1
summary: Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad
cves:
- CVE-2025-4922
ghsas:
- GHSA-rx97-6c62-55mf
references:
- advisory: https://github.com/advisories/GHSA-rx97-6c62-55mf
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-4922
- web: https://discuss.hashicorp.com/t/hcsec-2025-12-nomad-vulnerable-to-incorrect-acl-policy-lookup-attached-to-a-job/75396
source:
id: GHSA-rx97-6c62-55mf
created: 2025-07-21T17:09:05.299016816Z
review_status: UNREVIEWED