Skip to content
nomadGHSA-cj2h-ww36-v932

Improper Certificate Validation in HashiCorp Nomad

High9.8CVE-2020-7956 · Published May 18, 2021 · updated Aug 21, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
< 0.10.30.10.3
Details and references

HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-295
Also known as
CVE-2020-7956, GO-2022-0821

More nomad advisories

All
DateAdvisory
May 182021Allocation of Resources Without Limits or Throttling in HashiCorp Nomad
CVE-2020-7218High7.5fixed in 0.10.3
Jun 242021Improper network isolation in Hashicorp Nomad
CVE-2021-32575Medium6.5fixed in 0.12.12, 1.0.5
Jun 242021Improper Privilege Management in HashiCorp Nomad
CVE-2021-3283High7.5fixed in 0.12.10, 1.0.3
Sep 82021Privilege escalation in Hashicorp Nomad
CVE-2021-37218High8.8fixed in 1.0.10, 1.1.4
Dec 102021Improper Authentication in HashiCorp Nomad
CVE-2021-43415High8.8fixed in 1.0.14, 1.1.8, 1.2.1
Feb 152022HashiCorp Nomad Artifact Download Race Condition
CVE-2022-24686Medium5.9fixed in 1.0.18, 1.1.12, 1.2.6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.