CVE Vulnerabilities

CVE-2021-32575

Published: Jun 17, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
3.3 LOW
AV:A/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged tasks on the same node. Fixed in 0.12.12, 1.0.5, and 1.1.0 RC1.

Affected Software

NameVendorStart VersionEnd Version
NomadHashicorp*1.0.4 (including)
NomadUbuntubionic*
NomadUbuntufocal*
NomadUbuntugroovy*
NomadUbuntuhirsute*
NomadUbuntutrusty*
NomadUbuntuxenial*

References