NomadGHSA-7v3g-4878-5qrf
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL
Medium6.5CVE-2022-41606 · Published Oct 12, 2022 · updated May 20, 2025
HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | < 1.2.13 | 1.2.13 |
| >= 1.3.0, < 1.3.6 | 1.3.6 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-20
- Also known as
- CVE-2022-41606, GO-2022-1062
More Nomad advisories
All Nomad| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 142023 | Nomad Job Submitter Privilege Escalation Using Workload Identity | High8.8 | 1.5.1 |
| Feb 172023 | Uncontrolled Resource Consumption in Hashicorp Nomad | Medium6.5 | 1.2.16+2 more |
| Nov 102022 | HashiCorp Nomad vulnerable to Insufficient Session Expiration | Low2.7 | 1.4.2 |
| Nov 102022 | HashiCorp Nomad vulnerable to non-sensitive metadata exposure | Medium5.0 | 1.4.2 |
| Jun 32022 | Privilege escalation in Hashicorp Nomad | Critical9.8 | 1.1.14+2 more |
| May 242022 | Hashicorp Nomad Access Control Issues | Critical9.8 | 0.9.2 |