CVE Vulnerabilities

CVE-2022-24684

Published: Feb 15, 2022 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

HashiCorp Nomad and Nomad Enterprise 0.9.0 through 1.0.16, 1.1.11, and 1.2.5 allow operators with job-submit capabilities to use the spread stanza to panic server agents. Fixed in 1.0.18, 1.1.12, and 1.2.6.

Affected Software

NameVendorStart VersionEnd Version
NomadHashicorp0.9.0 (including)1.0.18 (excluding)
NomadHashicorp1.1.0 (including)1.1.12 (excluding)
NomadHashicorp1.2.0 (including)1.2.6 (excluding)
NomadUbuntubionic*
NomadUbuntufocal*
NomadUbuntutrusty*
NomadUbuntuxenial*

References