Skip to content
NomadGHSA-25qx-vfw2-fw8r

Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking

Medium5.8CVE-2024-7625 · Published Aug 15, 2024 · updated Sep 25, 2024

In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
>= 0.6.1, < 1.6.141.6.14
>= 1.7.0, < 1.7.111.7.11
>= 1.8.0, < 1.8.31.8.3
Details and references

More Nomad advisories

All Nomad
Advisory
Hashicorp Nomad Incorrect Privilege Assignment vulnerability
High8.1Jun 11, 2025
Nomad: secrets in logs
Medium6.5Mar 10, 2025
Hashicorp Nomad Incorrect Privilege Assignment vulnerability
Medium6.5Dec 20, 2024
Hashicorp Nomad Incorrect Authorization vulnerability
Medium7.7Nov 7, 2024
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration
High7.7Jul 23, 2024
HashiCorp Nomad vulnerable to symlink attacks
High7.7Feb 8, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.