NomadGHSA-gwmc-6795-qghj
HashiCorp Nomad Artifact Download Race Condition
Medium5.9CVE-2022-24686 · Published Feb 15, 2022 · updated Aug 21, 2024
HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destination. This issue is fixed in 1.0.18, 1.1.12, and 1.2.6.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | >= 0.3.0, < 1.0.18 | 1.0.18 |
| >= 1.1.0, < 1.1.12 | 1.1.12 | |
| >= 1.2.0, < 1.2.6 | 1.2.6 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-362
- Also known as
- CVE-2022-24686, GO-2022-0600
- nvd.nist.gov/vuln/detail/CVE-2022-24686
- github.com/hashicorp/nomad/issues/12036
- discuss.hashicorp.com
- discuss.hashicorp.com/t/hcsec-2022-01-nomad-artifact-download-race-condition/35559
- github.com/hashicorp/nomad
- github.com/hashicorp/nomad/releases/tag/v1.2.6
- security.netapp.com/advisory/ntap-20220318-0008
More Nomad advisories
All Nomad| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 12022 | HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling | High7.5 | 1.0.17+2 more |
| Feb 182022 | Arbitrary file reads in HashiCorp Nomad | High7.5 | 1.0.18+2 more |
| Feb 162022 | Nomad Spread Job Stanza May Trigger Panic in Servers | Medium6.5 | 1.0.18+2 more |
| Feb 152022 | Path Traversal in HashiCorp Nomad | Medium6.5 | 0.10.8+2 more |
| Feb 152022 | Hashicorp Nomad Information Exposure Through Environmental Variables | Medium5.3 | 0.9.5 |
| Feb 152022 | Use After Free in HashiCorp Nomad | Critical9.1 | 0.10.6+2 more |