Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2jhh-5xm2-j4gf

Опубликовано: 10 дек. 2021
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Improper Authentication in HashiCorp Nomad

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

Пакеты

Наименование

github.com/hashicorp/nomad

go
Затронутые версииВерсия исправления

< 1.0.14

1.0.14

Наименование

github.com/hashicorp/nomad

go
Затронутые версииВерсия исправления

>= 1.1.0, < 1.1.8

1.1.8

Наименование

github.com/hashicorp/nomad

go
Затронутые версииВерсия исправления

>= 1.2.0, < 1.2.1

1.2.1

EPSS

Процентиль: 64%
0.01182
Низкий

8.8 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 4 лет назад

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

CVSS3: 8.8
redhat
больше 4 лет назад

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

CVSS3: 8.8
nvd
больше 4 лет назад

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

CVSS3: 8.8
debian
больше 4 лет назад

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, w ...

EPSS

Процентиль: 64%
0.01182
Низкий

8.8 High

CVSS3

Дефекты

CWE-287