Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Nomad Event Stream Subscriber Using a Token with TTL Receives Updates Until Garbage Collected
Vulnerability Description
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
不充分的会话过期机制
Vulnerability Title
HashiCorp Nomad 代码问题漏洞
Vulnerability Description
HashiCorp Nomad是美国HashiCorp公司的一个简单灵活的调度器和编排器。用于在本地和云中大规模管理容器和非容器化应用程序。 HashiCorp Nomad和Nomad Enterprise 1.4.0至1.4.1版本存在代码问题漏洞,该漏洞源于事件流订阅者可以使用带有TTL的令牌接收更新,直到令牌垃圾被收集。
CVSS Information
N/A
Vulnerability Type
N/A