Database/Control plane, storage & DevOps
HashiCorp Nomad Enterprise: Jobs using the policy-override option bypass mandatory Sentinel policies
CVSS 7.6CVE-2025-3744Control plane, storage & DevOpscurated
Impact
Jobs using the policy-override option bypass mandatory Sentinel policies
Who can reach it
Network (remote)
What to do
Control-plane: upgrade Nomad 1.10.1/1.9.9/1.8.13; audit recently submitted jobs
References
Related entries
- Grafana: Client path traversal + open redirectCVE-2025-4123 · GrafanaHigh
- Sidero Omni: Reader role can read the full CA secrets bundle of an imported Talos clusterCVE-2026-45726 · Sidero Omni (ImportedClusterSecrets resource access rules)High
- rsync SSL modes: server TLS certificates are not validated, so an on-path attacker can read the transferCVE-2026-70454 · rsync (openssl mode) and rsync-ssl (stunnel mode) TLS server certificate validationHigh
- Red Hat Ansible Automation Platform automation-controller (custom Credential Type env injector): The custom CredentialCVE-2026-84706 · Red Hat Ansible Automation Platform automation-controller (custom Credential Type env injector)High
- OpenZFS (sharenfs export generation): When an NFS share is exported to IPv6 addresses via sharenfs, OpenZFS silentlyCVE-2013-20001 · OpenZFS (sharenfs export generation)High
- Ceph CephX authentication protocol: An attacker who sniffs the storage network can replay a CephX authenticationCVE-2018-1128 · Ceph CephX authentication protocolHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.