CVE-2025-3744 Details
Description
Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.
A vulnerability in HashiCorp Nomad Enterprise jobs allows the policy override option to bypass mandatory Sentinel policies. This issue is present in Nomad Enterprise versions prior to 1.10.0, 1.9.8, and 1.8.12. The vulnerability arises because hard mandatory Sentinel policies can be ignored when the policy-override flag is used during job submission, leading to the execution of jobs that violate these critical policy constraints.
Users should evaluate the risk associated with this vulnerability and consider upgrading to Nomad Enterprise versions 1.10.1, 1.9.9, or 1.8.13.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hashicorp nomad | < 1.8.13 >= 1.9.0, < 1.9.9 1.10.0 - 1.10.0 beta1 1.10.0 rc1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 15, 2025 | Initial Analysis | [email protected] |
| May 13, 2025 | New CVE Received | [email protected] |