CVE Vulnerabilities

CVE-2022-30324

Published: Jun 02, 2022 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.

Affected Software

Name Vendor Start Version End Version
Nomad Hashicorp 0.2.0 (including) 1.1.14 (excluding)
Nomad Hashicorp 1.2.0 (including) 1.2.8 (excluding)
Nomad Hashicorp 1.3.0 (including) 1.3.0 (including)
Nomad Ubuntu bionic *

References