CVE-2025-3744

Source
https://cve.org/CVERecord?id=CVE-2025-3744
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3744.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-3744
Published
2025-05-13T18:40:08.281Z
Modified
2026-07-15T02:14:30.893342844Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L CVSS Calculator
Summary
Nomad Vulnerable To Violation Of Mandatory Sentinel Policies in Nomad Job Submissions via Policy Override
Details

Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/3xxx/CVE-2025-3744.json",
    "cna_assigner": "HashiCorp",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "1.10.1"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-266"
    ]
}
References

Affected packages

Git / github.com/hashicorp/nomad

Affected ranges

Type
GIT
Repo
https://github.com/hashicorp/nomad
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*",
        "cpe:2.3:a:hashicorp:nomad:1.10.0:-:*:*:enterprise:*:*:*"
    ],
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.8.13"
        },
        {
            "introduced": "1.9.0"
        },
        {
            "fixed": "1.9.9"
        },
        {
            "introduced": "1.10.0-NA"
        },
        {
            "last_affected": "1.10.0-NA"
        }
    ]
}

Affected versions

1.*
1.10.0-NA
ent-changelog-1.*
ent-changelog-1.6.13
ent-changelog-1.7.10
ent-changelog-1.8.11
ent-changelog-1.8.5
ent-changelog-1.8.7
ent-changelog-1.8.9
Other
show
v0.*
v0.0.0
v0.1.0
v0.1.1
v0.1.2
v0.10.0-beta1
v0.2.0
v0.2.1
v0.2.2
v0.2.3
v0.2.3-rc1
v0.3.0-rc2
v0.3.1
v0.3.2
v0.3.2-rc1
v0.3.2-rc2
v0.3rc1
v0.4.0
v0.4.0-rc1
v0.4.0-rc2
v0.4.1
v0.4.1-rc1
v0.5.0
v0.5.0-rc1
v0.5.0-rc2
v0.5.1
v0.5.1-rc1
v0.5.1-rc2
v0.5.2
v0.5.2-rc1
v0.5.3
v0.5.5
v0.5.5-rc1
v0.5.5-rc2
v0.5.6
v0.5.6-rc1
v0.6.0
v0.6.0-rc1
v0.6.0-rc2
v0.6.1
v0.6.2
v0.6.3-rc1
v0.7.0
v0.7.0-rc1
v0.7.0-rc2
v0.7.0-rc3
v0.7.1
v0.7.1+pro
v0.7.1-rc1
v0.7.1-rc1+pro
v0.8.0
v0.8.0+pro
v0.8.0-rc1
v0.8.0-rc1+pro
v0.8.2
v0.8.3
v0.8.4
v0.8.4-rc1
v0.9.0
v0.9.0-beta1
v0.9.0-beta2
v0.9.0-beta3
v0.9.0-rc1
v0.9.0-rc2
v0.9.2
v0.9.2-rc1
v0.9.3
v0.9.4
v0.9.4-rc1
v1.*
v1.10.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-3744.json"