CVE-2023-3300

Source
https://cve.org/CVERecord?id=CVE-2023-3300
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-3300.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-3300
Aliases
Downstream
Published
2023-07-19T23:35:26.153Z
Modified
2026-07-15T01:48:51.337602138Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Nomad Search API Leaks Information About CSI Plugins
Details

HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. Fixed in 1.6.0, 1.5.7, and 1.4.1.

Database specific
{
    "cwe_ids": [
        "CWE-266"
    ],
    "cna_assigner": "HashiCorp",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/3xxx/CVE-2023-3300.json"
}
References

Affected packages

Git / github.com/hashicorp/nomad

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/nomad
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*",
        "cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "0.11.0"
        },
        {
            "last_affected": "1.4.1"
        },
        {
            "introduced": "1.5.0"
        },
        {
            "last_affected": "1.5.6"
        }
    ],
    "source": "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-3300.json"