CVE Vulnerabilities

CVE-2022-24683

Published: Feb 17, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.

Affected Software

Name Vendor Start Version End Version
Nomad Hashicorp 0.9.2 (including) 1.0.18 (excluding)
Nomad Hashicorp 1.1.0 (including) 1.1.12 (excluding)
Nomad Hashicorp 1.2.0 (including) 1.2.6 (excluding)
Nomad Ubuntu bionic *
Nomad Ubuntu trusty *
Nomad Ubuntu xenial *

References