PT-2021-4118 · Hashicorp · Hashicorp Nomad+1

Published

2021-05-12

·

Updated

2024-08-21

·

CVE-2021-32575

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions HashiCorp Nomad and Nomad Enterprise versions 1.0.4 and earlier
Description The issue is related to an error in bridge networking mode, allowing ARP spoofing from other bridged tasks on the same node. This could potentially allow a remote attacker to impact data integrity.
Recommendations For HashiCorp Nomad and Nomad Enterprise versions 1.0.4 and earlier, update to version 1.0.5 or later to resolve the issue. As a temporary workaround, consider restricting network access to minimize the risk of exploitation.

Fix

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

BDU:2021-04708
CVE-2021-32575
GHSA-VF6Q-9F2F-MWHV
GO-2022-0709

Affected Products

Hashicorp Nomad
Nomad Enterprise