Vulnerability Description
HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applies to nomad/client/allocrunner/taskrunner/template.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Nomad | >= 0.5.0, < 0.9.5 |
Related Weaknesses (CWE)
References
- https://advisories.gitlab.com/advisory/advgo_github_com_hashicorp_nomad_client_aThird Party Advisory
- https://www.hashicorp.com/blog/category/nomadProductVendor Advisory
- https://advisories.gitlab.com/advisory/advgo_github_com_hashicorp_nomad_client_aThird Party Advisory
- https://www.hashicorp.com/blog/category/nomadProductVendor Advisory
FAQ
What is CVE-2019-14802?
CVE-2019-14802 is a vulnerability with a CVSS score of 5.3 (MEDIUM). HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applies to nomad/client/all...
How severe is CVE-2019-14802?
CVE-2019-14802 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-14802?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Nomad.