CVE-2025-1296 Details
Description
Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19.
A vulnerability exists in HashiCorp Nomad Community and Enterprise editions, allowing unintentional exposure of sensitive tokens in audit logs. This issue affects Nomad Community Edition versions 1.0.0 through 1.9.6 and Nomad Enterprise versions 1.0.0 through 1.9.6, 1.8.10, and 1.7.18. The vulnerability arises from a logging utility that records unredacted workload identity tokens and client secret tokens, which could be accessed by unauthorized individuals, potentially leading to impersonation of users or access to protected resources.
Users are advised to upgrade to Nomad Community Edition 1.9.7 or Nomad Enterprise 1.9.7, 1.8.11, or 1.7.19.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://discuss.hashicorp.com/t/hcsec-2025-04-nomad-exposes-sensitive-workload-identity-and-client-secret-token-in-audit-logs/73737 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hashicorp nomad | >= 1.0.0, < 1.7.19 >= 1.0.0, < 1.9.7 >= 1.8.0, < 1.8.11 >= 1.9.0, < 1.9.7 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 18, 2025 | Initial Analysis | [email protected] |
| Mar 10, 2025 | New CVE Received | [email protected] |