Skip to content
nomadGHSA-526x-rm7j-v389

Privilege escalation in Hashicorp Nomad

Critical9.8CVE-2022-30324 · Published Jun 3, 2022 · updated Aug 21, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
>= 0.2.0, < 1.1.141.1.14
>= 1.2.0, < 1.2.81.2.8
>= 1.3.0, < 1.3.11.3.1
Details and references

HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Also known as
CVE-2022-30324, GO-2022-0732

More nomad advisories

All
DateAdvisory
May 242022Hashicorp Nomad Access Control Issues
CVE-2019-12618Critical9.8fixed in 0.9.2
Mar 12022HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling
CVE-2022-24685High7.5fixed in 1.0.17, 1.1.12, 1.2.6
Feb 182022Arbitrary file reads in HashiCorp Nomad
CVE-2022-24683High7.5fixed in 1.0.18, 1.1.12, 1.2.6
Feb 162022Nomad Spread Job Stanza May Trigger Panic in Servers
CVE-2022-24684Medium6.5fixed in 1.0.18, 1.1.12, 1.2.6
Feb 152022Path Traversal in HashiCorp Nomad
CVE-2020-28348Medium6.5fixed in 0.10.8, 0.11.7, 0.12.8
Feb 152022Hashicorp Nomad Information Exposure Through Environmental Variables
CVE-2019-14802Medium5.3fixed in 0.9.5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.