Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Nomad Exposes Sensitive Workload Identity and Client Secret Token in Audit Logs
Vulnerability Description
Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过日志文件的信息暴露
Vulnerability Title
HashiCorp Nomad Enterprise 日志信息泄露漏洞
Vulnerability Description
HashiCorp Nomad Enterprise是美国HashiCorp公司的一个 Nomad 软件的专业版。 HashiCorp Nomad Enterprise存在日志信息泄露漏洞,该漏洞源于审计日志中无意暴露了工作负载身份令牌和客户端密钥令牌。
CVSS Information
N/A
Vulnerability Type
N/A