Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Mar 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 10 Mar 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19. | |
Title | Nomad Exposes Sensitive Workload Identity and Client Secret Token in Audit Logs | |
Weaknesses | CWE-532 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: HashiCorp
Published: 2025-03-10T18:02:21.579Z
Updated: 2025-03-11T20:18:55.186Z
Reserved: 2025-02-14T01:10:26.947Z
Link: CVE-2025-1296

Updated: 2025-03-11T20:18:50.353Z

Status : Received
Published: 2025-03-10T18:15:30.237
Modified: 2025-03-10T18:15:30.237
Link: CVE-2025-1296

No data.