nomadGHSA-2w2v-xcr9-mj4m
Hashicorp Nomad Access Control Issues
Critical9.8CVE-2019-12618 · Published May 24, 2022 · updated Aug 20, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | >= 0.9.0, < 0.9.2 | 0.9.2 |
Details and references
HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-269
- Also known as
- CVE-2019-12618, GO-2023-1928
More nomad advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 32022 | Privilege escalation in Hashicorp Nomad CVE-2022-30324Critical9.8fixed in 1.1.14, 1.2.8, 1.3.1 | Critical9.8 | 1.1.14, 1.2.8, 1.3.1 |
| Mar 12022 | HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling CVE-2022-24685High7.5fixed in 1.0.17, 1.1.12, 1.2.6 | High7.5 | 1.0.17, 1.1.12, 1.2.6 |
| Feb 182022 | Arbitrary file reads in HashiCorp Nomad CVE-2022-24683High7.5fixed in 1.0.18, 1.1.12, 1.2.6 | High7.5 | 1.0.18, 1.1.12, 1.2.6 |
| Feb 162022 | Nomad Spread Job Stanza May Trigger Panic in Servers CVE-2022-24684Medium6.5fixed in 1.0.18, 1.1.12, 1.2.6 | Medium6.5 | 1.0.18, 1.1.12, 1.2.6 |
| Feb 152022 | Path Traversal in HashiCorp Nomad CVE-2020-28348Medium6.5fixed in 0.10.8, 0.11.7, 0.12.8 | Medium6.5 | 0.10.8, 0.11.7, 0.12.8 |
| Feb 152022 | Hashicorp Nomad Information Exposure Through Environmental Variables CVE-2019-14802Medium5.3fixed in 0.9.5 | Medium5.3 | 0.9.5 |