7.6

CVE-2025-3744

Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HashicorpNomad SwEditionenterprise Version < 1.8.13
HashicorpNomad SwEditionenterprise Version >= 1.9.0 < 1.9.9
HashicorpNomad Version1.10.0 Update- SwEditionenterprise
HashicorpNomad Version1.10.0 Updatebeta1 SwEditionenterprise
HashicorpNomad Version1.10.0 Updaterc1 SwEditionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.07% 0.217
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.6 2.8 4.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
security@hashicorp.com 7.6 2.8 4.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
CWE-266 Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.