{"schema_version":"1.9.0","id":"CVE-2024-12678","published":"2024-12-20T01:49:40.583Z","modified":"2026-08-12T03:51:47.845877949Z","aliases":["GHSA-hr68-hvgv-xxqf","GO-2024-3354"],"related":["SUSE-SU-2025:0060-1","openSUSE-SU-2024:14608-1"],"summary":"Nomad Allocations Vulnerable To Privilege Escalation Within A Namespace Using Unredacted Workload Identity Tokens","details":"Nomad Community and Nomad Enterprise (\"Nomad\") allocations are vulnerable to privilege escalation within a namespace through unredacted workload identity tokens. This vulnerability, identified as CVE-2024-12678, is fixed in Nomad Community Edition 1.9.4 and Nomad Enterprise 1.9.4, 1.8.8, and 1.7.16.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hashicorp/nomad","events":[{"introduced":"ebaabc9e5ead691dbf1509ed8755ef1e24d4ddf7"},{"fixed":"fe9b78d1b4bd30e5f872c5a5da8b51ad5e00142a"},{"fixed":"5e49fcdb7be26941b6c7ad3ed6661bd37e70a9d8"},{"introduced":"28b82e4b2259fae5a62e2ed47395334bea5a24c4"},{"fixed":"f8de4a252eecfc051286b3a14bfc73adb1598035"},{"introduced":"7ad36851ec02f875e0814775ecf1df0229f0a615"},{"fixed":"5e49fcdb7be26941b6c7ad3ed6661bd37e70a9d8"}],"database_specific":{"cpe":["cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*","cpe:2.3:a:hashicorp:nomad:*:*:*:*:community:*:*:*"],"extracted_events":[{"introduced":"1.4.0"},{"fixed":"1.7.16"},{"fixed":"1.9.4"},{"introduced":"1.8.0"},{"fixed":"1.8.8"},{"introduced":"1.9.0"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-12678.json"}}],"references":[{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2024-29-nomad-allocations-vulnerable-to-privilege-escalation-within-a-namespace-using-unredacted-workload-identity-token/72119"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/12xxx/CVE-2024-12678.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12678"},{"type":"PACKAGE","url":"https://github.com/hashicorp/nomad"}],"database_specific":{"cna_assigner":"HashiCorp","cwe_ids":["CWE-266"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/12xxx/CVE-2024-12678.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}