nomadGHSA-vf6q-9f2f-mwhv
Improper network isolation in Hashicorp Nomad
Medium6.5CVE-2021-32575 · Published Jun 24, 2021 · updated Aug 21, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | >= 1.0.0, < 1.0.5 | 1.0.5 |
| < 0.12.12 | 0.12.12 |
Details and references
HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged tasks on the same node. Fixed in 0.12.12, 1.0.5, and 1.1.0 RC1.
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-1100
- Also known as
- CVE-2021-32575, GO-2022-0709
More nomad advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 242021 | Improper Privilege Management in HashiCorp Nomad CVE-2021-3283High7.5fixed in 0.12.10, 1.0.3 | High7.5 | 0.12.10, 1.0.3 |
| May 182021 | Improper Certificate Validation in HashiCorp Nomad CVE-2020-7956High9.8fixed in 0.10.3 | High9.8 | 0.10.3 |
| May 182021 | Allocation of Resources Without Limits or Throttling in HashiCorp Nomad CVE-2020-7218High7.5fixed in 0.10.3 | High7.5 | 0.10.3 |
| Sep 82021 | Privilege escalation in Hashicorp Nomad CVE-2021-37218High8.8fixed in 1.0.10, 1.1.4 | High8.8 | 1.0.10, 1.1.4 |
| Dec 102021 | Improper Authentication in HashiCorp Nomad CVE-2021-43415High8.8fixed in 1.0.14, 1.1.8, 1.2.1 | High8.8 | 1.0.14, 1.1.8, 1.2.1 |
| Feb 152022 | HashiCorp Nomad Artifact Download Race Condition CVE-2022-24686Medium5.9fixed in 1.0.18, 1.1.12, 1.2.6 | Medium5.9 | 1.0.18, 1.1.12, 1.2.6 |