nomadGHSA-2w5v-x29g-jw7j
Hashicorp Nomad Incorrect Authorization vulnerability
Medium7.7CVE-2024-10975 · Published Nov 7, 2024 · updated Nov 8, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | <= 1.9.1 | No fix yet |
Details and references
Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, identified as CVE-2024-10975, is fixed in Nomad Community Edition 1.9.2 and Nomad Enterprise 1.9.2, 1.8.7, and 1.7.15.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-863
- Also known as
- CVE-2024-10975, GO-2024-3262
More nomad advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 202024 | Hashicorp Nomad Incorrect Privilege Assignment vulnerability CVE-2024-12678Medium6.5fixed in 1.9.4 | Medium6.5 | 1.9.4 |
| Aug 152024 | Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking CVE-2024-7625Medium5.8fixed in 1.6.14, 1.7.11, 1.8.3 | Medium5.8 | 1.6.14, 1.7.11, 1.8.3 |
| Jul 232024 | HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration CVE-2024-6717High7.7fixed in 1.8.2 | High7.7 | 1.8.2 |
| Mar 102025 | Nomad is vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs CVE-2025-1296Medium6.5no fix yet | Medium6.5 | No fix yet |
| Jun 112025 | Hashicorp Nomad Incorrect Privilege Assignment vulnerability CVE-2025-4922High8.1fixed in 1.10.2 | High8.1 | 1.10.2 |
| Feb 82024 | HashiCorp Nomad vulnerable to symlink attacks CVE-2024-1329High7.7fixed in 1.5.14, 1.6.7, 1.7.4 | High7.7 | 1.5.14, 1.6.7, 1.7.4 |