VDB

CVE-2025-1296

CVE-2025-1296 PUBLISHED CVSS 6.5 MEDIUM

Nomad is vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs

EPSS 0.19% · 40.3th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.19%
40.3th percentile

Affected Products

VendorProductVersions
HashiCorpNomad Enterprise1.0.0, 1.0.0
github.comhashicorp/nomad0, 0
hashicorpnomad1.9.0, 1.0.0, 1.8.0
HashiCorpNomad1.0.0, 1.0.0

Timeline

  • Mar 10, 2025 CVE Published
  • Mar 10, 2025 Coalition ESS Score
  • Mar 10, 2025 PoC Published
  • Mar 11, 2025 EPSS Score
  • Mar 11, 2025 PoC Published
  • Mar 14, 2025 CVE Updated
  • Mar 25, 2025 EPSS Score
  • Apr 7, 2025 EPSS Score
  • Apr 21, 2025 EPSS Score
  • May 4, 2025 EPSS Score
  • May 18, 2025 EPSS Score
  • Jun 1, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›