NomadGHSA-6hv3-7c34-4hx8
Hashicorp Nomad Information Exposure Through Environmental Variables
Medium5.3CVE-2019-14802 · Published Feb 15, 2022 · updated Aug 21, 2024
In Nomad before version 0.9.5, when rendering a task template, all environment variables were available to the rendering task. As a fix, only task environment variables are used.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | < 0.9.5 | 0.9.5 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200, CWE-526
- Also known as
- CVE-2019-14802, GO-2022-0634
- nvd.nist.gov/vuln/detail/CVE-2019-14802
- github.com/hashicorp/nomad/pull/6055
- github.com/hashicorp/nomad/commit/e8238305ef0b9ef37be3efd86a8d34bfbed5f63f
- advisories.gitlab.com/advisory/advgo_github_com_hashicorp_nomad_client_allocrunner_taskrunner_template_GMS_2022_818.html
- cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14802
- github.com/hashicorp/nomad
- github.com/hashicorp/nomad/releases/tag/v0.9.5
- www.hashicorp.com/blog/category/nomad
More Nomad advisories
All Nomad| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 12022 | HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling | High7.5 | 1.0.17+2 more |
| Feb 182022 | Arbitrary file reads in HashiCorp Nomad | High7.5 | 1.0.18+2 more |
| Feb 162022 | Nomad Spread Job Stanza May Trigger Panic in Servers | Medium6.5 | 1.0.18+2 more |
| Feb 152022 | Path Traversal in HashiCorp Nomad | Medium6.5 | 0.10.8+2 more |
| Feb 152022 | Use After Free in HashiCorp Nomad | Critical9.1 | 0.10.6+2 more |
| Feb 152022 | HashiCorp Nomad Artifact Download Race Condition | Medium5.9 | 1.0.18+2 more |