First published: Tue Apr 28 2020(Updated: )
HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could cause arbitrary JavaScript to execute in the web UI. Fixed in 0.10.5.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Nomad | >=0.3<0.10.5 | |
HashiCorp Nomad | >=0.3<0.10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-10944.
The title of this vulnerability is 'HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability'.
The severity of CVE-2020-10944 is medium with a CVSS score of 5.4.
HashiCorp Nomad and Nomad Enterprise versions up to 0.10.4 are affected.
To fix CVE-2020-10944, update HashiCorp Nomad and Nomad Enterprise to version 0.10.5 or higher.