PT-2020-12438 · Hashicorp · Nomad Enterprise+1

Published

2020-04-28

·

Updated

2020-05-06

·

CVE-2020-10944

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Nomad and Nomad Enterprise versions 0.10.4 and earlier
Description The issue allows files from a malicious workload to cause arbitrary JavaScript to execute in the web UI, due to a cross-site scripting vulnerability.
Recommendations For versions 0.10.4 and earlier, update to version 0.10.5 to resolve the issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-10944

Affected Products

Nomad
Nomad Enterprise