Skip to content
nomadGHSA-2w2v-xcr9-mj4m

Hashicorp Nomad Access Control Issues

Critical9.8CVE-2019-12618 · Published May 24, 2022 · updated Aug 20, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
>= 0.9.0, < 0.9.20.9.2
Details and references

HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-269
Also known as
CVE-2019-12618, GO-2023-1928

More nomad advisories

All
DateAdvisory
Jun 32022Privilege escalation in Hashicorp Nomad
CVE-2022-30324Critical9.8fixed in 1.1.14, 1.2.8, 1.3.1
Mar 12022HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling
CVE-2022-24685High7.5fixed in 1.0.17, 1.1.12, 1.2.6
Feb 182022Arbitrary file reads in HashiCorp Nomad
CVE-2022-24683High7.5fixed in 1.0.18, 1.1.12, 1.2.6
Feb 162022Nomad Spread Job Stanza May Trigger Panic in Servers
CVE-2022-24684Medium6.5fixed in 1.0.18, 1.1.12, 1.2.6
Feb 152022Path Traversal in HashiCorp Nomad
CVE-2020-28348Medium6.5fixed in 0.10.8, 0.11.7, 0.12.8
Feb 152022Hashicorp Nomad Information Exposure Through Environmental Variables
CVE-2019-14802Medium5.3fixed in 0.9.5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.