
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-12678 affects Nomad Community and Nomad Enterprise ("Nomad") allocations, making them vulnerable to privilege escalation within a namespace through unredacted workload identity tokens. The vulnerability was discovered in December 2024 and affects Nomad Community Edition from 1.4.0 up to 1.9.3 and Nomad Enterprise from 1.4.0 up to 1.9.3, 1.8.7, and 1.7.15 (HashiCorp Discussion).
The vulnerability stems from the exposure of Workload Identity tokens through the Read Allocation API or alloc command. These tokens provide access to workload-associated variables and service discovery. When combined with workload-associated ACL policies, users with namespace:read access can potentially escalate privileges and access additional policies for any workload within the namespace. The vulnerability has been assigned a CVSS v3.1 base score of 6.5 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N (HashiCorp Discussion).
The vulnerability allows users with namespace:read access to potentially escalate their privileges and access additional policies for any workload within the namespace, compromising the intended access control boundaries (HashiCorp Discussion).
The vulnerability has been fixed in Nomad Community Edition 1.9.4 and Nomad Enterprise versions 1.9.4, 1.8.8, and 1.7.16. Organizations are advised to evaluate their risk and upgrade to these patched versions. Users should refer to the Nomad Upgrade Guides for version-specific upgrade instructions (HashiCorp Discussion).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."