PT-2022-8093 · Hashicorp · Hashicorp Nomad
Published
2022-02-15
·
Updated
2024-08-21
·
CVE-2019-14802
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HashiCorp Nomad versions 0.5.0 through 0.9.4
Description
The issue reveals unintended environment variables to the rendering task during template rendering. This applies to the nomad/client/allocrunner/taskrunner/template module.
Recommendations
For HashiCorp Nomad versions 0.5.0 through 0.9.4, update to version 0.9.5 to resolve the issue. As a temporary workaround, consider restricting access to sensitive environment variables until the update is applied.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hashicorp Nomad