Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 881269 (CVE-2022-3866, CVE-2022-3867) - sys-cluster/nomad: multiple vulnerabilities
Summary: sys-cluster/nomad: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: CVE-2022-3866, CVE-2022-3867
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2022-11-14 05:19 UTC by John Helmert III
Modified: 2022-12-27 03:06 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-11-14 05:19:36 UTC
CVE-2022-3866 (https://discuss.hashicorp.com/t/hcsec-2022-25-nomad-s-workload-identity-token-can-list-non-sensitive-metadata-for-nomad-paths/46167):

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.

CVE-2022-3867 (https://discuss.hashicorp.com/t/hcsec-2022-26-nomad-s-event-stream-subscriber-using-acl-token-with-ttl-receive-updates-until-garbage-collected/46168):

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.

Please bump to 1.4.2.
Comment 1 Larry the Git Cow gentoo-dev 2022-12-27 03:04:04 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=427a7e41116651ab440672115ae6402d3711d36a

commit 427a7e41116651ab440672115ae6402d3711d36a
Author:     John Helmert III <ajak@gentoo.org>
AuthorDate: 2022-12-27 03:01:42 +0000
Commit:     John Helmert III <ajak@gentoo.org>
CommitDate: 2022-12-27 03:03:53 +0000

    sys-cluster/nomad: drop 1.2.13, 1.4.1
    
    Bug: https://bugs.gentoo.org/881269
    Signed-off-by: John Helmert III <ajak@gentoo.org>

 sys-cluster/nomad/Manifest            |  4 ----
 sys-cluster/nomad/nomad-1.2.13.ebuild | 44 -----------------------------------
 sys-cluster/nomad/nomad-1.4.1.ebuild  | 44 -----------------------------------
 3 files changed, 92 deletions(-)