CVE-2020-27195: Use After Free
Published Oct 22, 2020
·Updated
HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6
Affected Software
9 affected componentsFixes available
go/github.com/hashicorp/nomad>=0.12.0<0.12.6
0.12.6
go/github.com/hashicorp/nomad>=0.11.0<0.11.5
0.11.5
go/github.com/hashicorp/nomad>=0.9.0<0.10.6
0.10.6
HashiCorp Nomad>=0.9.0<=0.10.5
HashiCorp Nomad>=0.9.0<=0.10.5
HashiCorp Nomad>=0.11.0<=0.11.4
HashiCorp Nomad>=0.11.0<=0.11.4
HashiCorp Nomad>=0.12.0<=0.12.5
HashiCorp Nomad>=0.12.0<=0.12.5
Event History
Oct 22, 2020
CVE Published
via MITRE·04:19 PM
Data Sourced
via MITRE·04:19 PM
Description
Feb 15, 2022
Advisory Published
01:57 AM
Frequently Asked Questions
1
What is the vulnerability ID for this HashiCorp Nomad vulnerability?
The vulnerability ID for this HashiCorp Nomad vulnerability is CVE-2020-27195.
2
What is the severity of CVE-2020-27195?
The severity of CVE-2020-27195 is critical with a CVSS score of 9.1.
3
What is the affected software version range for CVE-2020-27195?
The affected software versions for CVE-2020-27195 range from 0.9.0 up to 0.12.5 for HashiCorp Nomad and Nomad Enterprise.
4
How can the client file sandbox feature be subverted in HashiCorp Nomad and Nomad Enterprise?
The client file sandbox feature can be subverted in HashiCorp Nomad and Nomad Enterprise using either the template or artifact stanzas.
5
How can I fix CVE-2020-27195?
You can fix CVE-2020-27195 by updating to version 0.12.6, 0.11.5, or 0.10.6 of HashiCorp Nomad or Nomad Enterprise.