PT-2021-23842 · Hashicorp · Nomad+1

Published

2021-12-03

·

Updated

2024-08-21

·

CVE-2021-43415

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp Nomad and Nomad Enterprise versions 1.0.13 and earlier, 1.1.7 and earlier, 1.2.0 and earlier
Description The issue allowed authenticated users with job submission capabilities to bypass the configured allowed image paths when the QEMU task driver was enabled.
Recommendations For versions 1.0.13 and earlier, update to version 1.0.14 or later. For versions 1.1.7 and earlier, update to version 1.1.8 or later. For versions 1.2.0 and earlier, update to version 1.2.1 or later.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2021-43415
GHSA-2JHH-5XM2-J4GF
GO-2022-0573

Affected Products

Nomad
Nomad Enterprise