NomadGHSA-35qp-xq9f-2rjx
Improper Privilege Management in HashiCorp Nomad
High7.5CVE-2021-3283 · Published Jun 24, 2021 · updated Aug 21, 2024
HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can access processes associated with other tasks on the same node. Fixed in 0.12.10, and 1.0.3.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | >= 1.0.0, < 1.0.3 | 1.0.3 |
| < 0.12.10 | 0.12.10 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-269
- Also known as
- CVE-2021-3283, GO-2022-0622
More Nomad advisories
All Nomad| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 152022 | HashiCorp Nomad Artifact Download Race Condition | Medium5.9 | 1.0.18+2 more |
| Dec 102021 | Improper Authentication in HashiCorp Nomad | High8.8 | 1.0.14+2 more |
| Sep 82021 | Privilege escalation in Hashicorp Nomad | High8.8 | 1.0.10+1 more |
| Jun 242021 | Improper network isolation in Hashicorp Nomad | Medium6.5 | 0.12.12+1 more |
| May 182021 | Improper Certificate Validation in HashiCorp Nomad | High9.8 | 0.10.3 |
| May 182021 | Allocation of Resources Without Limits or Throttling in HashiCorp Nomad | High7.5 | 0.10.3 |