Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-0937

Опубликовано: 12 фев. 2025
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.

A flaw was discovered in Hashicorp Nomad. In affected versions of this package, the vulnerability is exploitable when reading from the event stream endpoint with a wildcard namespace, which can be used to bypass the ACL policy checks that would not otherwise permit access to a given namespace due to a discrepancy in how ACL wildcards are validated.

Отчет

HashiCorp Nomad is a third party dependency in Red Hat Distributed Tracing. The affected codebase of HashiCorp Nomad is not shipped in Red Hat Distributed Tracing.

Меры по смягчению последствий

No mitigation is available for this issue other than updating the affected package to the version containing the fix.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift distributed tracing 3rhosdt/opentelemetry-collector-rhel8Not affected
Red Hat OpenShift distributed tracing 3rhosdt/opentelemetry-operator-bundleNot affected
Red Hat OpenShift distributed tracing 3rhosdt/opentelemetry-rhel8-operatorNot affected
Red Hat OpenShift distributed tracing 3rhosdt/opentelemetry-target-allocator-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2345327nomad: Nomad Vulnerable To Event Stream Namespace ACL Policy Bypass Through Wildcard Namespace

EPSS

Процентиль: 3%
0.00018
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
4 месяца назад

Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.

CVSS3: 7.1
nvd
4 месяца назад

Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.

CVSS3: 7.1
debian
4 месяца назад

Nomad Community and Nomad Enterprise ("Nomad") event stream configured ...

CVSS3: 7.1
redos
4 месяца назад

Уязвимость nomad

CVSS3: 7.1
github
4 месяца назад

Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.

EPSS

Процентиль: 3%
0.00018
Низкий

7.1 High

CVSS3