Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2145 | HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. Fixed in 1.6.0, 1.5.7, and 1.4.1. |
Github GHSA |
GHSA-v5fm-hr72-27hx | Nomad Search API Leaks Information About CSI Plugins |
Thu, 24 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Sep 2024 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-266 |
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2024-10-24T19:48:48.228Z
Reserved: 2023-06-16T18:48:08.987Z
Link: CVE-2023-3300
Updated: 2024-08-02T06:48:08.579Z
Status : Modified
Published: 2023-07-20T00:15:10.527
Modified: 2024-11-21T08:16:57.577
Link: CVE-2023-3300
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA