nomadGHSA-h43v-26r7-7j4c
Allocation of Resources Without Limits or Throttling in HashiCorp Nomad
High7.5CVE-2020-7218 · Published May 18, 2021 · updated Aug 21, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | < 0.10.3 | 0.10.3 |
Details and references
HashiCorp Nomad and Nomad Enterprise before 0.10.3 allow unbounded resource usage. ### Specific Go Packages Affected github.com/hashicorp/nomad/command/agent
More nomad advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 182021 | Improper Certificate Validation in HashiCorp Nomad CVE-2020-7956High9.8fixed in 0.10.3 | High9.8 | 0.10.3 |
| Jun 242021 | Improper network isolation in Hashicorp Nomad CVE-2021-32575Medium6.5fixed in 0.12.12, 1.0.5 | Medium6.5 | 0.12.12, 1.0.5 |
| Jun 242021 | Improper Privilege Management in HashiCorp Nomad CVE-2021-3283High7.5fixed in 0.12.10, 1.0.3 | High7.5 | 0.12.10, 1.0.3 |
| Sep 82021 | Privilege escalation in Hashicorp Nomad CVE-2021-37218High8.8fixed in 1.0.10, 1.1.4 | High8.8 | 1.0.10, 1.1.4 |
| Dec 102021 | Improper Authentication in HashiCorp Nomad CVE-2021-43415High8.8fixed in 1.0.14, 1.1.8, 1.2.1 | High8.8 | 1.0.14, 1.1.8, 1.2.1 |
| Feb 152022 | HashiCorp Nomad Artifact Download Race Condition CVE-2022-24686Medium5.9fixed in 1.0.18, 1.1.12, 1.2.6 | Medium5.9 | 1.0.18, 1.1.12, 1.2.6 |