NomadGHSA-2jhh-5xm2-j4gf
Improper Authentication in HashiCorp Nomad
High8.8CVE-2021-43415 · Published Dec 10, 2021 · updated Aug 21, 2024
HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | < 1.0.14 | 1.0.14 |
| >= 1.1.0, < 1.1.8 | 1.1.8 | |
| >= 1.2.0, < 1.2.1 | 1.2.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-287
- Also known as
- CVE-2021-43415, GO-2022-0573
More Nomad advisories
All Nomad| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 182022 | Arbitrary file reads in HashiCorp Nomad | High7.5 | 1.0.18+2 more |
| Feb 162022 | Nomad Spread Job Stanza May Trigger Panic in Servers | Medium6.5 | 1.0.18+2 more |
| Feb 152022 | Use After Free in HashiCorp Nomad | Critical9.1 | 0.10.6+2 more |
| Feb 152022 | Hashicorp Nomad Information Exposure Through Environmental Variables | Medium5.3 | 0.9.5 |
| Feb 152022 | Path Traversal in HashiCorp Nomad | Medium6.5 | 0.10.8+2 more |
| Feb 152022 | HashiCorp Nomad Artifact Download Race Condition | Medium5.9 | 1.0.18+2 more |