HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.