Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-12678

Опубликовано: 20 дек. 2024
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace through unredacted workload identity tokens. This vulnerability, identified as CVE-2024-12678, is fixed in Nomad Community Edition 1.9.4 and Nomad Enterprise 1.9.4, 1.8.8, and 1.7.16.

A flaw was found in hashicorp/nomad. Affected versions of this package are vulnerable to privilege escalation within a namespace through unredacted workload identity tokens.

Отчет

HashiCorp/Nomad is a third party dependency in Red Hat Distributed Tracing. The affected codebase of HashiCorp/Nomad is not shipped in Red Hat Distributed Tracing.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift distributed tracing 3rhosdt/opentelemetry-collector-rhel8Not affected
Red Hat OpenShift distributed tracing 3rhosdt/opentelemetry-operator-bundleNot affected
Red Hat OpenShift distributed tracing 3rhosdt/opentelemetry-rhel8-operatorNot affected
Red Hat OpenShift distributed tracing 3rhosdt/opentelemetry-target-allocator-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2333453github.com/hashicorp/nomad: Nomad Allocations Vulnerable To Privilege Escalation Within A Namespace Using Unredacted Workload Identity Tokens

EPSS

Процентиль: 21%
0.00065
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
6 месяцев назад

Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace through unredacted workload identity tokens. This vulnerability, identified as CVE-2024-12678, is fixed in Nomad Community Edition 1.9.4 and Nomad Enterprise 1.9.4, 1.8.8, and 1.7.16.

CVSS3: 6.5
nvd
6 месяцев назад

Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace through unredacted workload identity tokens. This vulnerability, identified as CVE-2024-12678, is fixed in Nomad Community Edition 1.9.4 and Nomad Enterprise 1.9.4, 1.8.8, and 1.7.16.

CVSS3: 6.5
debian
6 месяцев назад

Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnera ...

CVSS3: 6.5
redos
4 месяца назад

Уязвимость nomad

CVSS3: 6.5
github
6 месяцев назад

Hashicorp Nomad Incorrect Privilege Assignment vulnerability

EPSS

Процентиль: 21%
0.00065
Низкий

6.5 Medium

CVSS3