Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2024-7625

около 2 лет назад

In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability.

CVSS3: 5.8
EPSS: Низкий
nvd логотип

CVE-2024-7625

около 2 лет назад

In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability.

CVSS3: 5.8
EPSS: Низкий
debian логотип

CVE-2024-7625

около 2 лет назад

In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.1 ...

CVSS3: 5.8
EPSS: Низкий
github логотип

GHSA-25qx-vfw2-fw8r

около 2 лет назад

Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking

CVSS3: 5.8
EPSS: Низкий
fstec логотип

BDU:2024-07001

около 2 лет назад

Уязвимость оркестратора приложений Nomad, связанная с некорректным внешним управлением именем или путем файла при загрузке данных, позволяющая нарушителю создать архив, который распакует файл по путям за пределами предполагаемого каталога распределения

CVSS3: 5.8
EPSS: Низкий
redos логотип

ROS-20240910-05

около 2 лет назад

Уязвимость nomad

CVSS3: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-7625

In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability.

CVSS3: 5.8
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-7625

In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability.

CVSS3: 5.8
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-7625

In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.1 ...

CVSS3: 5.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-25qx-vfw2-fw8r

Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking

CVSS3: 5.8
0%
Низкий
около 2 лет назад
fstec логотип
BDU:2024-07001

Уязвимость оркестратора приложений Nomad, связанная с некорректным внешним управлением именем или путем файла при загрузке данных, позволяющая нарушителю создать архив, который распакует файл по путям за пределами предполагаемого каталога распределения

CVSS3: 5.8
0%
Низкий
около 2 лет назад
redos логотип
ROS-20240910-05

Уязвимость nomad

CVSS3: 5.8
0%
Низкий
около 2 лет назад

Уязвимостей на страницу