PT-2021-23435 · Hashicorp · Nomad Enterprise+2

Published

2021-10-07

·

Updated

2021-10-15

·

CVE-2021-41865

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp Nomad and Nomad Enterprise versions 1.1.1 through 1.1.5
Description The issue allows authenticated users with job submission capabilities to cause a denial of service by submitting incomplete job specifications when using a Consul mesh gateway and host networking mode.
Recommendations For versions 1.1.1 through 1.1.5, update to version 1.1.6 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-41865

Affected Products

Hashicorp Consul
Nomad
Nomad Enterprise