CVE Vulnerabilities

CVE-2020-27195

Published: Oct 22, 2020 | Modified: Nov 02, 2020
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
7.1 MODERATE
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Ubuntu
LOW

HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6

Affected Software

Name Vendor Start Version End Version
Nomad Hashicorp 0.9.0 (including) 0.10.5 (including)
Nomad Hashicorp 0.11.0 (including) 0.11.4 (including)
Nomad Hashicorp 0.12.0 (including) 0.12.5 (including)
Nomad Ubuntu bionic *
Nomad Ubuntu groovy *
Nomad Ubuntu hirsute *
Nomad Ubuntu trusty *

References