Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2jhh-5xm2-j4gf

Опубликовано: 10 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Improper Authentication in HashiCorp Nomad

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

Пакеты

Наименование

github.com/hashicorp/nomad

go
Затронутые версииВерсия исправления

< 1.0.14

1.0.14

Наименование

github.com/hashicorp/nomad

go
Затронутые версииВерсия исправления

>= 1.1.0, < 1.1.8

1.1.8

Наименование

github.com/hashicorp/nomad

go
Затронутые версииВерсия исправления

>= 1.2.0, < 1.2.1

1.2.1

EPSS

Процентиль: 53%
0.00305
Низкий

8.8 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 4 лет назад

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

CVSS3: 8.8
redhat
около 4 лет назад

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

CVSS3: 8.8
nvd
около 4 лет назад

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

CVSS3: 8.8
debian
около 4 лет назад

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, w ...

EPSS

Процентиль: 53%
0.00305
Низкий

8.8 High

CVSS3

Дефекты

CWE-287