Skip to content
nomadGHSA-vf6q-9f2f-mwhv

Improper network isolation in Hashicorp Nomad

Medium6.5CVE-2021-32575 · Published Jun 24, 2021 · updated Aug 21, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
>= 1.0.0, < 1.0.51.0.5
< 0.12.120.12.12
Details and references

HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged tasks on the same node. Fixed in 0.12.12, 1.0.5, and 1.1.0 RC1.

CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-1100
Also known as
CVE-2021-32575, GO-2022-0709

More nomad advisories

All
DateAdvisory
Jun 242021Improper Privilege Management in HashiCorp Nomad
CVE-2021-3283High7.5fixed in 0.12.10, 1.0.3
May 182021Improper Certificate Validation in HashiCorp Nomad
CVE-2020-7956High9.8fixed in 0.10.3
May 182021Allocation of Resources Without Limits or Throttling in HashiCorp Nomad
CVE-2020-7218High7.5fixed in 0.10.3
Sep 82021Privilege escalation in Hashicorp Nomad
CVE-2021-37218High8.8fixed in 1.0.10, 1.1.4
Dec 102021Improper Authentication in HashiCorp Nomad
CVE-2021-43415High8.8fixed in 1.0.14, 1.1.8, 1.2.1
Feb 152022HashiCorp Nomad Artifact Download Race Condition
CVE-2022-24686Medium5.9fixed in 1.0.18, 1.1.12, 1.2.6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.