PT-2021-23435 · Hashicorp · Nomad Enterprise+2
Published
2021-10-07
·
Updated
2021-10-15
·
CVE-2021-41865
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
HashiCorp Nomad and Nomad Enterprise versions 1.1.1 through 1.1.5
Description
The issue allows authenticated users with job submission capabilities to cause a denial of service by submitting incomplete job specifications when using a Consul mesh gateway and host networking mode.
Recommendations
For versions 1.1.1 through 1.1.5, update to version 1.1.6 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hashicorp Consul
Nomad
Nomad Enterprise