CVE-2025-1296 PUBLISHED CVSS 6.5 MEDIUM

Nomad is vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs

EPSS 0.06% · 19.8th percentile

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.06%
19.8th percentile

Affected Products

VendorProductVersions
HashiCorpNomad Enterprise1.0.0, 1.0.0
github.comhashicorp/nomad0, 0
hashicorpnomad1.0.0, 1.0.0, 1.8.0
HashiCorpNomad1.0.0, 1.0.0

Timeline

References

Open in Interactive Console →