Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wqwc-x3rc-2xw6

Опубликовано: 12 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 6

Описание

HashiCorp Nomad’s exec2 task driver vulnerable to a symlink attack

HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2 task driver.

Пакеты

Наименование

github.com/hashicorp/nomad-driver-exec2

go
Затронутые версииВерсия исправления

< 0.1.2

0.1.2

EPSS

Процентиль: 3%
0.00129
Низкий

6 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 6
ubuntu
3 месяца назад

HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2 task driver.

CVSS3: 6
nvd
3 месяца назад

HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2 task driver.

CVSS3: 6
debian
3 месяца назад

HashiCorp Nomad\u2019s exec2 task driver prior to 0.1.2 is vulnerable ...

CVSS3: 6
fstec
3 месяца назад

Уязвимость драйвера задач exec2 для Nomad, связанная с некорректным определением символических ссылок перед доступом к файлу, позволяющая нарушителю получить доступ на чтение и запись произвольных файлов

EPSS

Процентиль: 3%
0.00129
Низкий

6 Medium

CVSS3

Дефекты

CWE-59