CVE-2025-1296
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 10, 2025
CWE ID 532
Summary
CVE-2025-1296 is a vulnerability affecting Nomad Community and Enterprise editions. It allows for unintentional exposure of workload identity tokens and client secret tokens in audit logs. This issue, if exploited, could lead to unauthorized access or data breaches. The vulnerability has been addressed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19. Users are recommended to update their systems to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.