Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3934-423w-4jq3

Опубликовано: 12 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 6

Описание

HashiCorp Nomad vulnerable to symlink attack

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

Пакеты

Наименование

github.com/hashicorp/nomad

go
Затронутые версииВерсия исправления

< 1.11.0-rc.1.0.20260512123500-2a09fd62c238

1.11.0-rc.1.0.20260512123500-2a09fd62c238

EPSS

Процентиль: 7%
0.00169
Низкий

6 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 6
ubuntu
3 месяца назад

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

CVSS3: 6
nvd
3 месяца назад

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.

CVSS3: 6
debian
3 месяца назад

HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to ...

CVSS3: 6
fstec
3 месяца назад

Уязвимость оркестратора приложений Nomad, связанная с некорректным определением символических ссылок перед доступом к файлу, позволяющая нарушителю получить доступ на чтение и запись произвольных файлов

CVSS3: 6
redos
25 дней назад

Уязвимость nomad

EPSS

Процентиль: 7%
0.00169
Низкий

6 Medium

CVSS3

Дефекты

CWE-59