Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-37218

Опубликовано: 07 сент. 2021
Источник: debian
EPSS Низкий

Описание

HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nomadremovedpackage

Примечания

  • https://discuss.hashicorp.com/t/hcsec-2021-21-nomad-raft-rpc-privilege-escalation/29023

  • https://github.com/hashicorp/nomad/pull/11089 (main)

  • https://github.com/hashicorp/nomad/commit/768d7c72a77e9c0415d92900753fc83e8822145a (release-1.1.4)

  • https://github.com/hashicorp/nomad/commit/61a922afcf12784281757402c8e0b61686ff855d (release-1.0.11)

EPSS

Процентиль: 38%
0.00166
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 4 лет назад

HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.

CVSS3: 8.8
redhat
больше 4 лет назад

HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.

CVSS3: 8.8
nvd
больше 4 лет назад

HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.

CVSS3: 8.8
github
больше 4 лет назад

Privilege escalation in Hashicorp Nomad

EPSS

Процентиль: 38%
0.00166
Низкий