← Back

CVE-2025-3744

nvd nist
Published: May 13, 2025Modified: May 15, 2025

JSON object

Loading...
7.6
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Exploitability: 2.8 / Impact: 4.7
Source: NVD

Description

Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.

Affected (5)

Products: Hashicorp: Nomad
1 product
Nomad
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Hashicorp
Before 1.8.13
From 1.9.0 to 1.9.9
Version 1.10.0
Version 1.10.0 beta1
Version 1.10.0 rc1

Timeline

No history available yet.