Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Schmichael

#13438of 53,624
19.8Total CVSS
Vulnerabilities · 2
Critical
2
PT-2020-19875
9.8
2020-01-31
Hashicorp · Nomad Enterprise · CVE-2020-7956
**Name of the Vulnerable Software and Affected Versions** HashiCorp Nomad and Nomad Enterprise versions up to 0.10.2 **Description** The issue concerns improper validation of role/region associated with TLS certificates used for mTLS RPC, making the system susceptible to privilege escalation. **Recommendations** For HashiCorp Nomad and Nomad Enterprise versions up to 0.10.2, update to version 0.10.3 to resolve the issue.
PT-2019-12895
10
2019-08-12
Hashicorp · Hashicorp Nomad · CVE-2019-12618
**Name of the Vulnerable Software and Affected Versions** HashiCorp Nomad versions 0.9.0 through 0.9.1 **Description** The issue is related to Incorrect Access Control via the exec driver. This affects the access control mechanism in HashiCorp Nomad, potentially allowing unauthorized access. **Recommendations** For HashiCorp Nomad versions 0.9.0 through 0.9.1, consider restricting access to the exec driver until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.