← Back

CVE-2025-1296

nvd nist
Published: Mar 10, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: security@hashicorp.com (Secondary)

Description

Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19.

Affected (4)

Products: Hashicorp: Nomad
1 product
Nomad
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Hashicorp
From 1.0.0 to 1.9.7
From 1.0.0 to 1.7.19
From 1.8.0 to 1.8.11
From 1.9.0 to 1.9.7

Timeline

No history available yet.