CVE-2020-10944: XSS
Published Apr 28, 2020
·Updated
HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could cause arbitrary JavaScript to execute in the web UI. Fixed in 0.10.5.
Affected Software
2 affected components
HashiCorp Nomad>=0.3<0.10.5
HashiCorp Nomad>=0.3<0.10.5
Remediation
Patch Available
Event History
Apr 28, 2020
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2020-10944.
2
What is the title of this vulnerability?
The title of this vulnerability is 'HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability'.
3
What is the severity of CVE-2020-10944?
The severity of CVE-2020-10944 is medium with a CVSS score of 5.4.
4
What software is affected by this vulnerability?
HashiCorp Nomad and Nomad Enterprise versions up to 0.10.4 are affected.
5
How do I fix CVE-2020-10944?
To fix CVE-2020-10944, update HashiCorp Nomad and Nomad Enterprise to version 0.10.5 or higher.