{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-15T22:49:22.018","vulnerabilities":[{"cve":{"id":"CVE-2025-1296","sourceIdentifier":"security@hashicorp.com","published":"2025-03-10T18:15:30.237","lastModified":"2025-12-18T14:41:48.977","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19."},{"lang":"es","value":"Nomad Community y Nomad Enterprise (“Nomad”) son vulnerables a la exposición involuntaria del token de identidad de la carga de trabajo y del token secreto del cliente en los registros de auditoría. Esta vulnerabilidad, identificada como CVE-2025-1296, está corregida en Nomad Community Edition 1.9.7 y Nomad Enterprise 1.9.7, 1.8.11 y 1.7.19."}],"metrics":{"cvssMetricV31":[{"source":"security@hashicorp.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@hashicorp.com","type":"Secondary","description":[{"lang":"en","value":"CWE-532"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"1.7.19","matchCriteriaId":"626AAF2A-C4BD-49A2-B937-0A77D64E30CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*","versionStartIncluding":"1.0.0","versionEndExcluding":"1.9.7","matchCriteriaId":"6A92234C-FAE7-41FD-BE67-031D5C60D17E"},{"vulnerable":true,"criteria":"cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.8.0","versionEndExcluding":"1.8.11","matchCriteriaId":"BFA81749-8501-417A-B3AD-5932FD1A6297"},{"vulnerable":true,"criteria":"cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.9.0","versionEndExcluding":"1.9.7","matchCriteriaId":"785B5C2C-A6BB-4696-B7CC-4E6E2B8F58A1"}]}]}],"references":[{"url":"https://discuss.hashicorp.com/t/hcsec-2025-04-nomad-exposes-sensitive-workload-identity-and-client-secret-token-in-audit-logs/73737","source":"security@hashicorp.com","tags":["Vendor Advisory"]}]}}]}