CVE-2025-1296

MEDIUM

Hashicorp Nomad < 1.7.19 - Log Information Exposure

Title source: rule
STIX 2.1

Description

Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19.

Scores

CVSS v3 6.5
EPSS 0.0019
EPSS Percentile 40.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-532
Status published
Products (3)
hashicorp/nomad 0Go
hashicorp/nomad 1.0.0 - 1.7.19
hashicorp/nomad 1.0.0 - 1.9.7
Published Mar 10, 2025
Tracked Since Feb 18, 2026