CVE-2025-1296

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 10, 2025
CWE ID 532

Summary

CVE-2025-1296 is a vulnerability affecting Nomad Community and Enterprise editions. It allows for unintentional exposure of workload identity tokens and client secret tokens in audit logs. This issue, if exploited, could lead to unauthorized access or data breaches. The vulnerability has been addressed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19. Users are recommended to update their systems to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share