CVE Vulnerabilities

CVE-2022-24684

Published: Feb 15, 2022 | Modified: Aug 08, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

HashiCorp Nomad and Nomad Enterprise 0.9.0 through 1.0.16, 1.1.11, and 1.2.5 allow operators with job-submit capabilities to use the spread stanza to panic server agents. Fixed in 1.0.18, 1.1.12, and 1.2.6.

Affected Software

Name Vendor Start Version End Version
Nomad Hashicorp 0.9.0 (including) 1.0.18 (excluding)
Nomad Hashicorp 1.1.0 (including) 1.1.12 (excluding)
Nomad Hashicorp 1.2.0 (including) 1.2.6 (excluding)

References