PT-2022-25981 · Hashicorp+1 · Nomad Enterprise+2

Published

2022-10-10

·

Updated

2025-05-26

·

CVE-2022-41606

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions HashiCorp Nomad and Nomad Enterprise versions 1.0.2 through 1.2.12 HashiCorp Nomad and Nomad Enterprise version 1.3.5
Description The issue allows jobs submitted with an artifact stanza using invalid S3 or GCS URLs to crash client agents.
Recommendations For HashiCorp Nomad and Nomad Enterprise versions 1.0.2 through 1.2.12, update to version 1.2.13 or later. For HashiCorp Nomad and Nomad Enterprise version 1.3.5, update to version 1.3.6 or later. As a temporary workaround, consider restricting the submission of jobs with artifact stanzas using invalid S3 or GCS URLs until a patch is applied.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-06169
CVE-2022-41606
GHSA-7V3G-4878-5QRF
GO-2022-1062

Affected Products

Hashicorp Nomad
Nomad Enterprise
Red Os