Skip to content
nomadGHSA-wmrx-57hm-mw7r

Arbitrary file reads in HashiCorp Nomad

High7.5CVE-2022-24683 · Published Feb 18, 2022 · updated Aug 21, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/hashicorp/nomad
Go
>= 0.9.2, < 1.0.181.0.18
>= 1.1.0, < 1.1.121.1.12
>= 1.2.0, < 1.2.61.2.6
Details and references

Nomad is an easy-to-use, flexible, and performant workload orchestrator that can deploy a mix of microservice, batch, containerized, and non-containerized applications. HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root. There are currently no known workarounds. Users are recommended to upgrade as soon as possible to avoid this issue.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
CVE-2022-24683, GO-2022-0584

More nomad advisories

All
DateAdvisory
Feb 162022Nomad Spread Job Stanza May Trigger Panic in Servers
CVE-2022-24684Medium6.5fixed in 1.0.18, 1.1.12, 1.2.6
Feb 152022Path Traversal in HashiCorp Nomad
CVE-2020-28348Medium6.5fixed in 0.10.8, 0.11.7, 0.12.8
Feb 152022Hashicorp Nomad Information Exposure Through Environmental Variables
CVE-2019-14802Medium5.3fixed in 0.9.5
Feb 152022Use After Free in HashiCorp Nomad
CVE-2020-27195Critical9.1fixed in 0.10.6, 0.11.5, 0.12.6
Feb 152022HashiCorp Nomad Artifact Download Race Condition
CVE-2022-24686Medium5.9fixed in 1.0.18, 1.1.12, 1.2.6
Mar 12022HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling
CVE-2022-24685High7.5fixed in 1.0.17, 1.1.12, 1.2.6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.