Описание
HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4.
A flaw was found in the HashiCorp Nomad package. A job submitted with a maliciously compressed source (for example, “Zip Bomb”) in an artifact stanza can cause excessive disk resource consumption, crashing a Nomad client agent.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Logging Subsystem for Red Hat OpenShift | openshift-logging/logging-loki-rhel8 | Not affected | ||
Logging Subsystem for Red Hat OpenShift | openshift-logging/lokistack-gateway-rhel9 | Not affected | ||
Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/thanos-rhel7 | Not affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-cluster-monitoring-operator | Not affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-installer | Not affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-prometheus | Not affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-prometheus-rhel9-operator | Not affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-prom-label-proxy | Not affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/ose-thanos-rhel8 | Not affected | ||
Red Hat OpenShift Container Platform 4 | openshift4/topology-aware-lifecycle-manager-rhel8-operator | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4.
HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4.
HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 job ...
Uncontrolled Resource Consumption in Hashicorp Nomad
Уязвимость оркестратора приложений Nomad, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.5 Medium
CVSS3