NomadGHSA-25qx-vfw2-fw8r
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking
Medium5.8CVE-2024-7625 · Published Aug 15, 2024 · updated Sep 25, 2024
In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | >= 0.6.1, < 1.6.14 | 1.6.14 |
| >= 1.7.0, < 1.7.11 | 1.7.11 | |
| >= 1.8.0, < 1.8.3 | 1.8.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-610
- Also known as
- CVE-2024-7625, GO-2024-3073
More Nomad advisories
All Nomad| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 112025 | Hashicorp Nomad Incorrect Privilege Assignment vulnerability | High8.1 | 1.10.2 |
| Mar 102025 | Nomad: secrets in logs | Medium6.5 | No fix yet |
| Dec 202024 | Hashicorp Nomad Incorrect Privilege Assignment vulnerability | Medium6.5 | 1.9.4 |
| Nov 72024 | Hashicorp Nomad Incorrect Authorization vulnerability | Medium7.7 | No fix yet |
| Jul 232024 | HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration | High7.7 | 1.8.2 |
| Feb 82024 | HashiCorp Nomad vulnerable to symlink attacks | High7.7 | 1.5.14+2 more |