Vulnerability Description
HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Nomad | >= 0.9.2, < 1.0.18 |
References
- https://discuss.hashicorp.comVendor Advisory
- https://discuss.hashicorp.com/t/hcsec-2022-02-nomad-alloc-filesystem-and-containVendor Advisory
- https://security.netapp.com/advisory/ntap-20220318-0008/Third Party Advisory
- https://discuss.hashicorp.comVendor Advisory
- https://discuss.hashicorp.com/t/hcsec-2022-02-nomad-alloc-filesystem-and-containVendor Advisory
- https://security.netapp.com/advisory/ntap-20220318-0008/Third Party Advisory
FAQ
What is CVE-2022-24683?
CVE-2022-24683 is a vulnerability with a CVSS score of 7.5 (HIGH). HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as ...
How severe is CVE-2022-24683?
CVE-2022-24683 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-24683?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Nomad.