Skip to content
NomadGHSA-c866-8gpw-p3mv

HashiCorp Nomad vulnerable to symlink attacks

High7.7CVE-2024-1329 · Published Feb 8, 2024 · updated Sep 26, 2024

HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. Fixed in Nomad 1.7.4, 1.6.7, 1.5.14.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
>= 1.5.13, < 1.5.141.5.14
>= 1.6.0, < 1.6.71.6.7
>= 1.7.3, < 1.7.41.7.4
Details and references

More Nomad advisories

All Nomad
Advisory
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking
Medium5.8Aug 15, 2024
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration
High7.7Jul 23, 2024
Nomad Search API Leaks Information About CSI Plugins
Medium5.3Jul 20, 2023
Nomad Caller ACL Token’s Secret ID is Exposed to Sentinel
Low3.4Jul 20, 2023
Nomad ACL Policies without Label are Applied to Unexpected Resources
Medium4.1Jul 20, 2023
Hashicorp Nomad ACLs Cannot Deny Access to Workload’s Own Variables
Medium5.3Jul 6, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.