PT-2021-21582 · Hashicorp · Nomad Enterprise+1

Published

2021-09-07

·

Updated

2024-08-21

·

CVE-2021-37218

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp Nomad and Nomad Enterprise versions prior to 1.0.10 HashiCorp Nomad and Nomad Enterprise versions prior to 1.1.4
Description The issue allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation.
Recommendations For HashiCorp Nomad and Nomad Enterprise versions prior to 1.0.10, update to version 1.0.10 or later. For HashiCorp Nomad and Nomad Enterprise versions prior to 1.1.4, update to version 1.1.4 or later.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2021-37218
GHSA-C8X3-RG72-FWWG
GO-2022-0591

Affected Products

Hashicorp Nomad
Nomad Enterprise