CVE Vulnerabilities

CVE-2020-27195

Published: Oct 22, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.1
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
7.1 MODERATE
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6

Affected Software

NameVendorStart VersionEnd Version
NomadHashicorp0.9.0 (including)0.10.5 (including)
NomadHashicorp0.11.0 (including)0.11.4 (including)
NomadHashicorp0.12.0 (including)0.12.5 (including)
NomadUbuntubionic*
NomadUbuntufocal*
NomadUbuntugroovy*
NomadUbuntuhirsute*
NomadUbuntutrusty*

References