| id: GO-2025-3758 |
| modules: |
| - module: github.com/hashicorp/nomad |
| versions: |
| - fixed: 1.10.2 |
| vulnerable_at: 1.10.1 |
| summary: Hashicorp Nomad Incorrect Privilege Assignment vulnerability in github.com/hashicorp/nomad |
| cves: |
| - CVE-2025-4922 |
| ghsas: |
| - GHSA-rx97-6c62-55mf |
| references: |
| - advisory: https://github.com/advisories/GHSA-rx97-6c62-55mf |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-4922 |
| - web: https://discuss.hashicorp.com/t/hcsec-2025-12-nomad-vulnerable-to-incorrect-acl-policy-lookup-attached-to-a-job/75396 |
| source: |
| id: GHSA-rx97-6c62-55mf |
| created: 2025-07-21T17:09:05.299016816Z |
| review_status: UNREVIEWED |