PT-2020-16990 · Hashicorp+1 · Nomad Enterprise+2
Tgross
·
Published
2020-11-24
·
Updated
2024-08-21
·
CVE-2020-28348
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HashiCorp Nomad and Nomad Enterprise versions 0.9.0 through 0.12.7
Description
The client Docker file sandbox feature in HashiCorp Nomad and Nomad Enterprise may be subverted when not explicitly disabled or when using a volume mount type. This issue is related to the
github.com/hashicorp/nomad/drivers/docker component.Recommendations
For versions 0.9.0 through 0.12.7, update to version 0.12.8, 0.11.7, or 0.10.8 to resolve the issue.
As a temporary workaround, consider disabling the client Docker file sandbox feature until a patch is available.
Restrict access to the
github.com/hashicorp/nomad/drivers/docker component to minimize the risk of exploitation.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docker
Nomad
Nomad Enterprise