Описание
HashiCorp Nomad vulnerable to symlink attack
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-6959
- https://github.com/hashicorp/nomad/commit/2a09fd62c23880ff306499ae03fe64628d82a23f
- https://discuss.hashicorp.com/t/hcsec-2026-14-nomad-arbitrary-file-read-write-on-client-host-through-symlink-attack/77416
- https://github.com/hashicorp/nomad/releases/tag/v2.0.1
Пакеты
github.com/hashicorp/nomad
< 1.11.0-rc.1.0.20260512123500-2a09fd62c238
1.11.0-rc.1.0.20260512123500-2a09fd62c238
Связанные уязвимости
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to ...
Уязвимость оркестратора приложений Nomad, связанная с некорректным определением символических ссылок перед доступом к файлу, позволяющая нарушителю получить доступ на чтение и запись произвольных файлов