nomadGHSA-526x-rm7j-v389
Privilege escalation in Hashicorp Nomad
Critical9.8CVE-2022-30324 · Published Jun 3, 2022 · updated Aug 21, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | >= 0.2.0, < 1.1.14 | 1.1.14 |
| >= 1.2.0, < 1.2.8 | 1.2.8 | |
| >= 1.3.0, < 1.3.1 | 1.3.1 |
Details and references
HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Also known as
- CVE-2022-30324, GO-2022-0732
More nomad advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 242022 | Hashicorp Nomad Access Control Issues CVE-2019-12618Critical9.8fixed in 0.9.2 | Critical9.8 | 0.9.2 |
| Mar 12022 | HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling CVE-2022-24685High7.5fixed in 1.0.17, 1.1.12, 1.2.6 | High7.5 | 1.0.17, 1.1.12, 1.2.6 |
| Feb 182022 | Arbitrary file reads in HashiCorp Nomad CVE-2022-24683High7.5fixed in 1.0.18, 1.1.12, 1.2.6 | High7.5 | 1.0.18, 1.1.12, 1.2.6 |
| Feb 162022 | Nomad Spread Job Stanza May Trigger Panic in Servers CVE-2022-24684Medium6.5fixed in 1.0.18, 1.1.12, 1.2.6 | Medium6.5 | 1.0.18, 1.1.12, 1.2.6 |
| Feb 152022 | Path Traversal in HashiCorp Nomad CVE-2020-28348Medium6.5fixed in 0.10.8, 0.11.7, 0.12.8 | Medium6.5 | 0.10.8, 0.11.7, 0.12.8 |
| Feb 152022 | Hashicorp Nomad Information Exposure Through Environmental Variables CVE-2019-14802Medium5.3fixed in 0.9.5 | Medium5.3 | 0.9.5 |