Skip to content
NomadGHSA-2jhh-5xm2-j4gf

Improper Authentication in HashiCorp Nomad

High8.8CVE-2021-43415 · Published Dec 10, 2021 · updated Aug 21, 2024

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
< 1.0.141.0.14
>= 1.1.0, < 1.1.81.1.8
>= 1.2.0, < 1.2.11.2.1
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-287
Also known as
CVE-2021-43415, GO-2022-0573

More Nomad advisories

All Nomad
Advisory
Arbitrary file reads in HashiCorp Nomad
High7.5Feb 18, 2022
Nomad Spread Job Stanza May Trigger Panic in Servers
Medium6.5Feb 16, 2022
Use After Free in HashiCorp Nomad
Critical9.1Feb 15, 2022
Hashicorp Nomad Information Exposure Through Environmental Variables
Medium5.3Feb 15, 2022
Path Traversal in HashiCorp Nomad
Medium6.5Feb 15, 2022
HashiCorp Nomad Artifact Download Race Condition
Medium5.9Feb 15, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.