HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
{
"cwe_ids": [
"CWE-613"
],
"severity": "LOW",
"github_reviewed": true,
"nvd_published_at": "2022-11-10T06:15:00Z",
"github_reviewed_at": "2022-11-10T23:51:03Z"
}