HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "1.0.10"
},
{
"introduced": "0"
},
{
"last_affected": "1.0.10"
},
{
"introduced": "1.1.1"
},
{
"fixed": "1.1.4"
},
{
"introduced": "1.1.1"
},
{
"fixed": "1.1.4"
}
]
}