PT-2020-16990 · Hashicorp+1 · Nomad Enterprise+2

Tgross

·

Published

2020-11-24

·

Updated

2024-08-21

·

CVE-2020-28348

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Nomad and Nomad Enterprise versions 0.9.0 through 0.12.7
Description The client Docker file sandbox feature in HashiCorp Nomad and Nomad Enterprise may be subverted when not explicitly disabled or when using a volume mount type. This issue is related to the github.com/hashicorp/nomad/drivers/docker component.
Recommendations For versions 0.9.0 through 0.12.7, update to version 0.12.8, 0.11.7, or 0.10.8 to resolve the issue. As a temporary workaround, consider disabling the client Docker file sandbox feature until a patch is available. Restrict access to the github.com/hashicorp/nomad/drivers/docker component to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-28348
GHSA-5X92-P4P5-33C4
GO-2022-0770

Affected Products

Docker
Nomad
Nomad Enterprise