CVE-2024-12678

Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace through unredacted workload identity tokens. This vulnerability, identified as CVE-2024-12678, is fixed in Nomad Community Edition 1.9.4 and Nomad Enterprise 1.9.4, 1.8.8, and 1.7.16.
Configurations

No configuration.

History

20 Dec 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-20 02:15

Updated : 2024-12-20 02:15


NVD link : CVE-2024-12678

Mitre link : CVE-2024-12678

CVE.ORG link : CVE-2024-12678


JSON object : View

Products Affected

No product.

CWE
CWE-266

Incorrect Privilege Assignment