Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp nomad |
|
| CPEs | cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:* cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:* |
|
| Vendors & Products |
Hashicorp
Hashicorp nomad |
Tue, 11 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Mar 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19. | |
| Title | Nomad Exposes Sensitive Workload Identity and Client Secret Token in Audit Logs | |
| Weaknesses | CWE-532 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2025-03-11T20:18:55.186Z
Reserved: 2025-02-14T01:10:26.947Z
Link: CVE-2025-1296
Updated: 2025-03-11T20:18:50.353Z
Status : Analyzed
Published: 2025-03-10T18:15:30.237
Modified: 2025-12-18T14:41:48.977
Link: CVE-2025-1296
No data.
OpenCVE Enrichment
No data.