Hashicorp

Nomad

36 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Published 20.07.2023 00:15:10
  • Last modified 21.11.2024 08:16:57

HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.

  • EPSS 0.04%
  • Published 20.07.2023 00:15:10
  • Last modified 21.11.2024 08:16:22

HashiCorp Nomad and Nomad Enterprise 0.7.0 up to 1.5.6 and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.

  • EPSS 0.36%
  • Published 05.04.2023 20:15:07
  • Last modified 21.11.2024 07:39:53

HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.

  • EPSS 0.15%
  • Published 14.03.2023 15:15:11
  • Last modified 21.11.2024 07:38:52

HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fixed in 1.5.1.

  • EPSS 0.34%
  • Published 14.03.2023 15:15:11
  • Last modified 21.11.2024 07:38:51

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and 1.5.1.

  • EPSS 0.24%
  • Published 16.02.2023 22:15:11
  • Last modified 21.11.2024 07:37:54

HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4.

  • EPSS 0.3%
  • Published 26.12.2022 21:15:10
  • Last modified 14.04.2025 18:15:18

HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applies to nomad/client/allocrunner/taskrunner/template.

  • EPSS 0.21%
  • Published 10.11.2022 06:15:11
  • Last modified 21.11.2024 07:20:23

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.

  • EPSS 0.23%
  • Published 10.11.2022 06:15:09
  • Last modified 21.11.2024 07:20:23

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.

  • EPSS 0.21%
  • Published 12.10.2022 00:15:10
  • Last modified 20.05.2025 16:15:23

HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.