Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wmrx-57hm-mw7r

Опубликовано: 18 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Arbitrary file reads in HashiCorp Nomad

Nomad is an easy-to-use, flexible, and performant workload orchestrator that can deploy a mix of microservice, batch, containerized, and non-containerized applications. HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root. There are currently no known workarounds. Users are recommended to upgrade as soon as possible to avoid this issue.

Пакеты

Наименование

github.com/hashicorp/nomad

go
Затронутые версииВерсия исправления

>= 0.9.2, < 1.0.18

1.0.18

Наименование

github.com/hashicorp/nomad

go
Затронутые версииВерсия исправления

>= 1.1.0, < 1.1.12

1.1.12

Наименование

github.com/hashicorp/nomad

go
Затронутые версииВерсия исправления

>= 1.2.0, < 1.2.6

1.2.6

EPSS

Процентиль: 64%
0.00474
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.

CVSS3: 7.5
nvd
почти 4 года назад

HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.

CVSS3: 7.5
debian
почти 4 года назад

HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and ...

EPSS

Процентиль: 64%
0.00474
Низкий

7.5 High

CVSS3

Дефекты

CWE-22