NomadGHSA-c866-8gpw-p3mv
HashiCorp Nomad vulnerable to symlink attacks
High7.7CVE-2024-1329 · Published Feb 8, 2024 · updated Sep 26, 2024
HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. Fixed in Nomad 1.7.4, 1.6.7, 1.5.14.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | >= 1.5.13, < 1.5.14 | 1.5.14 |
| >= 1.6.0, < 1.6.7 | 1.6.7 | |
| >= 1.7.3, < 1.7.4 | 1.7.4 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-59, CWE-610
- Also known as
- CVE-2024-1329, GO-2024-2538
- nvd.nist.gov/vuln/detail/CVE-2024-1329
- github.com/hashicorp/nomad/issues/19888
- github.com/hashicorp/nomad/commit/b3209cbc6921e703b0e9984ce70c10b378665834
- github.com/hashicorp/nomad/commit/d1721c7a6fc1833778086603f818a822a34f445a
- github.com/hashicorp/nomad/commit/de55da677a21ac7572c0f4a8cd9abd5473c47a70
- discuss.hashicorp.com/t/hcsec-2024-03-nomad-vulnerable-to-arbitrary-write-through-symlink-attack
- github.com/hashicorp/nomad
More Nomad advisories
All Nomad| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 152024 | Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking | Medium5.8 | 1.6.14+2 more |
| Jul 232024 | HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration | High7.7 | 1.8.2 |
| Jul 202023 | Nomad Search API Leaks Information About CSI Plugins | Medium5.3 | 1.4.11+1 more |
| Jul 202023 | Nomad Caller ACL Token’s Secret ID is Exposed to Sentinel | Low3.4 | 1.4.11+1 more |
| Jul 202023 | Nomad ACL Policies without Label are Applied to Unexpected Resources | Medium4.1 | 1.4.11+1 more |
| Jul 62023 | Hashicorp Nomad ACLs Cannot Deny Access to Workload’s Own Variables | Medium5.3 | 1.4.6+1 more |