[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2024-12678":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":19,"aliases":20,"duplicate_of":9,"upstream":23,"downstream":24,"duplicates":31,"related":32,"reserved_at":9,"published_at":35,"modified_at":36,"state":37,"summary":38,"references_raw":47,"kevs":75,"epss":76,"epss_history":79,"metrics":349,"affected":359},"CVE-2024-12678","Nomad Community and Nomad Enterprise (\"Nomad\") allocations are vulnerable to privilege escalation within a namespace through unredacted workload identity tokens. This vulnerability, identified as CVE-2024-12678, is fixed in Nomad Community Edition 1.9.4 and Nomad Enterprise 1.9.4, 1.8.8, and 1.7.16.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-266","Incorrect Privilege Assignment","A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.","weakness","Draft","Base",[],[],[21,22],"GHSA-hr68-hvgv-xxqf","GO-2024-3354",[],[25,27,29],{"_key":26},"UBUNTU-CVE-2024-12678",{"_key":28},"SUSE-SU-2025:0060-1",{"_key":30},"OPENSUSE-SU-2024:14608-1",[],[33,34],{"_key":28},{"_key":30},"2024-12-20T01:49:40.583Z","2024-12-20T17:08:12.684Z","Analyzed",{"cisa_kev":39,"cisa_ransomware":39,"cisa_vendor":9,"epss_severity":40,"epss_score":41,"severity":42,"severity_score":43,"severity_version":44,"severity_source":45,"severity_vector":46,"severity_status":37},false,"low",0.00409,"medium",6.5,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",[48,56,61,66,71],{"url":49,"sources":50,"tags":53},"https://discuss.hashicorp.com/t/hcsec-2024-29-nomad-allocations-vulnerable-to-privilege-escalation-within-a-namespace-using-unredacted-workload-identity-token/72119",[45,51,52],"nvd","osv_go",[54,55],"Vendor Advisory","WEB",{"url":57,"sources":58,"tags":59},"https://nvd.nist.gov/vuln/detail/CVE-2024-12678",[52],[60],"Advisory",{"url":62,"sources":63,"tags":64},"https://github.com/hashicorp/nomad/commit/359a71861ef044cb5d749a36ff0e44b172c8f1a6",[52],[55,65],"FIX",{"url":67,"sources":68,"tags":69},"https://github.com/hashicorp/nomad",[52],[70],"PACKAGE",{"url":72,"sources":73,"tags":74},"https://github.com/advisories/GHSA-hr68-hvgv-xxqf",[52],[60],[],{"date":77,"score":41,"percentile":78},"2026-06-04",0.61596,[80,84,87,90,93,96,99,102,105,108,111,114,117,120,123,127,130,133,135,138,141,144,147,150,153,156,159,162,164,167,169,172,175,178,181,184,187,190,193,196,200,203,206,209,212,215,218,221,224,227,230,233,236,239,242,244,247,250,253,256,259,262,265,268,271,274,277,280,283,286,289,292,295,298,301,303,306,309,312,315,318,321,324,327,330,333,337,340,343,346],{"date":81,"score":82,"percentile":83},"2025-11-04",0.00135,0.34004,{"date":85,"score":82,"percentile":86},"2025-11-05",0.33993,{"date":88,"score":82,"percentile":89},"2025-11-06",0.33995,{"date":91,"score":82,"percentile":92},"2025-11-07",0.34013,{"date":94,"score":82,"percentile":95},"2025-11-08",0.34008,{"date":97,"score":82,"percentile":98},"2025-11-09",0.33988,{"date":100,"score":82,"percentile":101},"2025-11-10",0.33935,{"date":103,"score":82,"percentile":104},"2025-11-11",0.33962,{"date":106,"score":82,"percentile":107},"2025-11-12",0.34009,{"date":109,"score":82,"percentile":110},"2025-11-13",0.34024,{"date":112,"score":82,"percentile":113},"2025-11-14",0.3403,{"date":115,"score":82,"percentile":116},"2025-11-15",0.34029,{"date":118,"score":82,"percentile":119},"2025-11-16",0.33999,{"date":121,"score":82,"percentile":122},"2025-11-17",0.33974,{"date":124,"score":125,"percentile":126},"2025-11-18",0.00172,0.33388,{"date":128,"score":125,"percentile":129},"2025-11-19",0.33402,{"date":131,"score":125,"percentile":132},"2025-11-20",0.33385,{"date":134,"score":82,"percentile":107},"2025-11-21",{"date":136,"score":82,"percentile":137},"2025-11-22",0.34012,{"date":139,"score":82,"percentile":140},"2025-11-23",0.33978,{"date":142,"score":82,"percentile":143},"2025-11-24",0.33954,{"date":145,"score":82,"percentile":146},"2025-11-25",0.33947,{"date":148,"score":82,"percentile":149},"2025-11-26",0.33946,{"date":151,"score":82,"percentile":152},"2025-11-27",0.33955,{"date":154,"score":82,"percentile":155},"2025-11-28",0.33936,{"date":157,"score":82,"percentile":158},"2025-11-29",0.33918,{"date":160,"score":82,"percentile":161},"2025-11-30",0.33898,{"date":163,"score":82,"percentile":119},"2025-12-01",{"date":165,"score":82,"percentile":166},"2025-12-02",0.34014,{"date":168,"score":82,"percentile":166},"2025-12-03",{"date":170,"score":82,"percentile":171},"2025-12-04",0.33908,{"date":173,"score":82,"percentile":174},"2025-12-05",0.33942,{"date":176,"score":82,"percentile":177},"2025-12-06",0.33943,{"date":179,"score":82,"percentile":180},"2025-12-07",0.33922,{"date":182,"score":82,"percentile":183},"2025-12-08",0.33934,{"date":185,"score":82,"percentile":186},"2025-12-09",0.33975,{"date":188,"score":82,"percentile":189},"2025-12-10",0.34031,{"date":191,"score":82,"percentile":192},"2025-12-11",0.34053,{"date":194,"score":82,"percentile":195},"2025-12-12",0.34082,{"date":197,"score":198,"percentile":199},"2025-12-13",0.0014,0.34846,{"date":201,"score":198,"percentile":202},"2025-12-14",0.34818,{"date":204,"score":198,"percentile":205},"2025-12-15",0.34777,{"date":207,"score":198,"percentile":208},"2025-12-16",0.34803,{"date":210,"score":198,"percentile":211},"2025-12-17",0.34856,{"date":213,"score":198,"percentile":214},"2025-12-18",0.34904,{"date":216,"score":198,"percentile":217},"2025-12-19",0.34925,{"date":219,"score":198,"percentile":220},"2025-12-20",0.34907,{"date":222,"score":198,"percentile":223},"2025-12-21",0.3485,{"date":225,"score":198,"percentile":226},"2025-12-22",0.34824,{"date":228,"score":198,"percentile":229},"2025-12-23",0.34821,{"date":231,"score":198,"percentile":232},"2025-12-24",0.34816,{"date":234,"score":198,"percentile":235},"2025-12-25",0.34881,{"date":237,"score":198,"percentile":238},"2025-12-26",0.34862,{"date":240,"score":198,"percentile":241},"2025-12-27",0.34876,{"date":243,"score":198,"percentile":205},"2025-12-28",{"date":245,"score":198,"percentile":246},"2025-12-29",0.34744,{"date":248,"score":198,"percentile":249},"2025-12-30",0.34735,{"date":251,"score":198,"percentile":252},"2025-12-31",0.34789,{"date":254,"score":198,"percentile":255},"2026-01-01",0.34937,{"date":257,"score":198,"percentile":258},"2026-01-02",0.34929,{"date":260,"score":198,"percentile":261},"2026-01-03",0.34913,{"date":263,"score":198,"percentile":264},"2026-01-04",0.34763,{"date":266,"score":198,"percentile":267},"2026-01-05",0.34747,{"date":269,"score":198,"percentile":270},"2026-01-06",0.34757,{"date":272,"score":198,"percentile":273},"2026-01-07",0.34773,{"date":275,"score":198,"percentile":276},"2026-01-08",0.34801,{"date":278,"score":198,"percentile":279},"2026-01-09",0.34795,{"date":281,"score":198,"percentile":282},"2026-01-10",0.34796,{"date":284,"score":198,"percentile":285},"2026-01-11",0.34775,{"date":287,"score":198,"percentile":288},"2026-01-12",0.34717,{"date":290,"score":198,"percentile":291},"2026-01-13",0.34701,{"date":293,"score":198,"percentile":294},"2026-01-14",0.34739,{"date":296,"score":198,"percentile":297},"2026-01-15",0.34731,{"date":299,"score":198,"percentile":300},"2026-01-16",0.34749,{"date":302,"score":198,"percentile":249},"2026-01-17",{"date":304,"score":198,"percentile":305},"2026-01-18",0.34672,{"date":307,"score":198,"percentile":308},"2026-01-19",0.3464,{"date":310,"score":198,"percentile":311},"2026-01-20",0.34625,{"date":313,"score":198,"percentile":314},"2026-01-21",0.34588,{"date":316,"score":198,"percentile":317},"2026-01-22",0.34566,{"date":319,"score":198,"percentile":320},"2026-01-23",0.34624,{"date":322,"score":198,"percentile":323},"2026-01-24",0.34637,{"date":325,"score":198,"percentile":326},"2026-01-25",0.34574,{"date":328,"score":198,"percentile":329},"2026-01-26",0.34486,{"date":331,"score":198,"percentile":332},"2026-01-27",0.34479,{"date":334,"score":335,"percentile":336},"2026-01-28",0.00216,0.44059,{"date":338,"score":335,"percentile":339},"2026-01-29",0.44049,{"date":341,"score":335,"percentile":342},"2026-01-30",0.44056,{"date":344,"score":335,"percentile":345},"2026-01-31",0.44068,{"date":347,"score":335,"percentile":348},"2026-02-01",0.44188,[350,355,357],{"source":45,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":351,"cvss_v4_0":9},{"baseScore":43,"baseSeverity":352,"vectorString":46,"impactScore":353,"exploitabilityScore":354},"MEDIUM",6,7.2,{"source":51,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":356,"cvss_v4_0":9},{"baseScore":43,"baseSeverity":352,"vectorString":46,"impactScore":353,"exploitabilityScore":354},{"source":52,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":358,"cvss_v4_0":9},{"baseScore":43,"baseSeverity":9,"vectorString":46,"impactScore":353,"exploitabilityScore":354},[360,373,393],{"ecosystem":361,"name":362,"vendor":363,"product":364,"cpe_part":9,"purl_type":365,"purl_namespace":363,"purl_name":364,"source":9,"versions":366},"Go","github.com/hashicorp/nomad","github.com/hashicorp","nomad","golang",[367],{"version":368,"is_range":369,"range_type":370,"version_start":9,"version_start_type":9,"version_end":371,"version_end_type":372,"fixed_in":9},"lt1_9_4",true,"semver","1.9.4","excluding",{"ecosystem":9,"name":374,"vendor":375,"product":364,"cpe_part":376,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":377},"Nomad","hashicorp","a",[378,384,386,390],{"version":379,"is_range":369,"range_type":380,"version_start":381,"version_start_type":382,"version_end":383,"version_end_type":372,"fixed_in":9},"gte1.4.0_lt1.7.16","cpe","1.4.0","including","1.7.16",{"version":385,"is_range":369,"range_type":380,"version_start":381,"version_start_type":382,"version_end":371,"version_end_type":372,"fixed_in":9},"gte1.4.0_lt1.9.4",{"version":387,"is_range":369,"range_type":380,"version_start":388,"version_start_type":382,"version_end":389,"version_end_type":372,"fixed_in":9},"gte1.8.0_lt1.8.8","1.8.0","1.8.8",{"version":391,"is_range":369,"range_type":380,"version_start":392,"version_start_type":382,"version_end":371,"version_end_type":372,"fixed_in":9},"gte1.9.0_lt1.9.4","1.9.0",{"ecosystem":9,"name":394,"vendor":375,"product":395,"cpe_part":376,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":396},"Nomad Enterprise","nomad enterprise",[397],{"version":398,"is_range":369,"range_type":45,"version_start":381,"version_start_type":382,"version_end":371,"version_end_type":372,"fixed_in":9},">= 1.4.0, \u003C 1.9.4"]