Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-1296 Nomad ACLs Can Not Deny Access to Workload's Own Variables #16349

Closed
tgross opened this issue Mar 6, 2023 · 0 comments
Closed
Assignees
Milestone

Comments

@tgross
Copy link
Member

tgross commented Mar 6, 2023

Summary:

A vulnerability was identified in Nomad and Nomad Enterprise (“Nomad”) such that a deny ACL capability could not be applied to a workload’s own variables. If included, the Nomad ACL system will silently fail to block access. This vulnerability, CVE-2023-1296, was fixed in Nomad 1.4.6 and 1.5.1.

Background:

Nomad 1.4.0 introduced the variables feature, and a new workload identity feature so that tasks can access their own variables without needing to create and pass a Nomad ACL token.

Details:

An OSS user reported an unexpected behavior where adding a policy with a deny capability did not deny access to a variable.

Remediation:

Customers should evaluate the risk associated with this issue and consider upgrading to Nomad 1.4.6, 1.5.1, or newer.

@tgross tgross added the type/bug label Mar 6, 2023
@tgross tgross modified the milestones: 1.5.x, 1.5.1 Mar 6, 2023
@tgross tgross self-assigned this Mar 6, 2023
@tgross tgross changed the title (placeholder) CVE-2023-1296 Nomad ACLs Can Not Deny Access to Workload's Own Variables Mar 13, 2023
@tgross tgross closed this as completed Mar 13, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant