Skip to content
nomadGHSA-2w5v-x29g-jw7j

Hashicorp Nomad Incorrect Authorization vulnerability

Medium7.7CVE-2024-10975 · Published Nov 7, 2024 · updated Nov 8, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
<= 1.9.1No fix yet
Details and references

Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, identified as CVE-2024-10975, is fixed in Nomad Community Edition 1.9.2 and Nomad Enterprise 1.9.2, 1.8.7, and 1.7.15.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-863
Also known as
CVE-2024-10975, GO-2024-3262

More nomad advisories

All
DateAdvisory
Dec 202024Hashicorp Nomad Incorrect Privilege Assignment vulnerability
CVE-2024-12678Medium6.5fixed in 1.9.4
Aug 152024Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking
CVE-2024-7625Medium5.8fixed in 1.6.14, 1.7.11, 1.8.3
Jul 232024HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration
CVE-2024-6717High7.7fixed in 1.8.2
Mar 102025Nomad is vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs
CVE-2025-1296Medium6.5no fix yet
Jun 112025Hashicorp Nomad Incorrect Privilege Assignment vulnerability
CVE-2025-4922High8.1fixed in 1.10.2
Feb 82024HashiCorp Nomad vulnerable to symlink attacks
CVE-2024-1329High7.7fixed in 1.5.14, 1.6.7, 1.7.4

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.