GHSA-9fmc-5fq4-5jwh, CVE-2022-3867
go/github.com/hashicorp/nomad
HashiCorp Nomad vulnerable to Insufficient Session Expiration
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
All versions starting from 1.4.0 before 1.4.2
Upgrade to version 1.4.2 or above.
2022-11-13
source |