CVE Vulnerabilities

CVE-2022-30324

Published: Jun 02, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.

Affected Software

NameVendorStart VersionEnd Version
NomadHashicorp0.2.0 (including)1.1.14 (excluding)
NomadHashicorp1.2.0 (including)1.2.8 (excluding)
NomadHashicorp1.3.0 (including)1.3.0 (including)
NomadUbuntubionic*
NomadUbuntufocal*

References