CVE Vulnerabilities

CVE-2022-41606

Published: Oct 12, 2022 | Modified: May 20, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io minimus.io echohq.com

HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.

Affected Software

Name Vendor Start Version End Version
Nomad Hashicorp 1.0.2 (including) 1.2.13 (excluding)
Nomad Hashicorp 1.3.0 (including) 1.3.6 (excluding)
Nomad Ubuntu bionic *
Nomad Ubuntu focal *
Nomad Ubuntu trusty *
Nomad Ubuntu xenial *

References