NomadGHSA-77cr-6gr8-7rr9
Use After Free in HashiCorp Nomad
Critical9.1CVE-2020-27195 · Published Feb 15, 2022 · updated Aug 21, 2024
HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | >= 0.9.0, < 0.10.6 | 0.10.6 |
| >= 0.11.0, < 0.11.5 | 0.11.5 | |
| >= 0.12.0, < 0.12.6 | 0.12.6 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-416
- Also known as
- CVE-2020-27195, GO-2022-0806
More Nomad advisories
All Nomad| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 12022 | HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling | High7.5 | 1.0.17+2 more |
| Feb 182022 | Arbitrary file reads in HashiCorp Nomad | High7.5 | 1.0.18+2 more |
| Feb 162022 | Nomad Spread Job Stanza May Trigger Panic in Servers | Medium6.5 | 1.0.18+2 more |
| Feb 152022 | Path Traversal in HashiCorp Nomad | Medium6.5 | 0.10.8+2 more |
| Feb 152022 | Hashicorp Nomad Information Exposure Through Environmental Variables | Medium5.3 | 0.9.5 |
| Feb 152022 | HashiCorp Nomad Artifact Download Race Condition | Medium5.9 | 1.0.18+2 more |