Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-43415

Опубликовано: 03 дек. 2021
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 6
CVSS3: 8.8

Описание

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

DNE

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-infra-legacy/trusty

DNE

esm-infra/xenial

DNE

focal

ignored

end of standard support, was needs-triage
hirsute

ignored

end of life
impish

DNE

jammy

DNE

Показывать по

EPSS

Процентиль: 53%
0.00305
Низкий

6 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
около 4 лет назад

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

CVSS3: 8.8
nvd
около 4 лет назад

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

CVSS3: 8.8
debian
около 4 лет назад

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, w ...

CVSS3: 8.8
github
около 4 лет назад

Improper Authentication in HashiCorp Nomad

EPSS

Процентиль: 53%
0.00305
Низкий

6 Medium

CVSS2

8.8 High

CVSS3