PT-2020-19472 · Hashicorp · Nomad+1

Published

2020-01-31

·

Updated

2024-08-21

·

CVE-2020-7218

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp Nomad and Nomad Enterprise versions prior to 0.10.3
Description The issue allows unbounded resource usage and is susceptible to unauthenticated denial of service. This affects the HTTP/RPC services.
Recommendations For versions prior to 0.10.3, update to version 0.10.3 to resolve the issue. As a temporary workaround, consider restricting access to the HTTP/RPC services to minimize the risk of exploitation.

Fix

Allocation of Resources Without Limits

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2020-7218
GHSA-H43V-26R7-7J4C
GO-2022-0840

Affected Products

Nomad
Nomad Enterprise