Improper Certificate Validation in HashiCorp Nomad
High severity
GitHub Reviewed
Published
May 18, 2021
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
May 13, 2021
Published to the GitHub Advisory Database
May 18, 2021
Last updated
Jan 9, 2023
HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.
References