Skip to content
NomadGHSA-c8x3-rg72-fwwg

Privilege escalation in Hashicorp Nomad

High8.8CVE-2021-37218 · Published Sep 8, 2021 · updated Aug 21, 2024

HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
< 1.0.101.0.10
>= 1.1.0, < 1.1.41.1.4
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-295
Also known as
CVE-2021-37218, GO-2022-0591

More Nomad advisories

All Nomad
Advisory
HashiCorp Nomad Artifact Download Race Condition
Medium5.9Feb 15, 2022
Improper Authentication in HashiCorp Nomad
High8.8Dec 10, 2021
Improper Privilege Management in HashiCorp Nomad
High7.5Jun 24, 2021
Improper network isolation in Hashicorp Nomad
Medium6.5Jun 24, 2021
Improper Certificate Validation in HashiCorp Nomad
High9.8May 18, 2021
Allocation of Resources Without Limits or Throttling in HashiCorp Nomad
High7.5May 18, 2021

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.