Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.
References
Configurations
Configuration 1 (hide)
|
History
15 May 2025, 16:45
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:hashicorp:nomad:1.10.0:-:*:*:enterprise:*:*:* cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:* cpe:2.3:a:hashicorp:nomad:1.10.0:beta1:*:*:enterprise:*:*:* cpe:2.3:a:hashicorp:nomad:1.10.0:rc1:*:*:enterprise:*:*:* |
|
CWE | NVD-CWE-noinfo | |
Summary |
|
|
First Time |
Hashicorp
Hashicorp nomad |
|
References | () https://discuss.hashicorp.com/t/hcsec-2025-08-nomad-enterprise-vulnerable-to-violation-of-mandatory-sentinel-policies-in-job-submissions-via-policy-override/74935 - Vendor Advisory |
13 May 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-13 19:15
Updated : 2025-05-15 16:45
NVD link : CVE-2025-3744
Mitre link : CVE-2025-3744
CVE.ORG link : CVE-2025-3744
JSON object : View
Products Affected
hashicorp
- nomad
CWE