CVE-2023-3300

MEDIUM5.3EPSS 0.81%

Nomad Search API Leaks Information About CSI Plugins

Published: 7/20/2023Modified: 4/5/2024
Also known as:GHSA-v5fm-hr72-27hxGO-2024-2671

Description

A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability, CVE-2023-3300, affects Nomad since 0.11 and was fixed in 1.6.0, 1.5.7, and 1.4.11.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References (5)