CVE Vulnerabilities

CVE-2024-6717

Externally Controlled Reference to a Resource in Another Sphere

Published: Jul 23, 2024 | Modified: Jan 02, 2026
CVSS 3.x
8.6
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.

Weakness

The product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.

Affected Software

Name Vendor Start Version End Version
Nomad Hashicorp 1.7.0 (including) 1.7.10 (excluding)
Nomad Hashicorp 1.6.12 (including) 1.6.12 (including)
Nomad Hashicorp 1.8.1 (including) 1.8.1 (including)
Nomad Ubuntu focal *

References