CVE Vulnerabilities

CVE-2021-3283

Published: Feb 01, 2021 | Modified: Feb 04, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can access processes associated with other tasks on the same node. Fixed in 0.12.10, and 1.0.3.

Affected Software

Name Vendor Start Version End Version
Nomad Hashicorp * 0.12.10 (excluding)
Nomad Hashicorp 1.0.0 (including) 1.0.3 (excluding)
Nomad Ubuntu bionic *
Nomad Ubuntu groovy *
Nomad Ubuntu hirsute *
Nomad Ubuntu trusty *

References