Vulnerability Description
HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could cause arbitrary JavaScript to execute in the web UI. Fixed in 0.10.5.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Nomad | >= 0.3, < 0.10.5 |
Related Weaknesses (CWE)
References
- https://github.com/hashicorp/nomad/issues/7468PatchThird Party Advisory
- https://github.com/hashicorp/nomad/issues/7468PatchThird Party Advisory
FAQ
What is CVE-2020-10944?
CVE-2020-10944 is a vulnerability with a CVSS score of 5.4 (MEDIUM). HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could cause arbitrary JavaScript to execute in the web UI. Fi...
How severe is CVE-2020-10944?
CVE-2020-10944 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-10944?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Nomad.