First published: Thu Oct 22 2020(Updated: )
HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/hashicorp/nomad | >=0.12.0<0.12.6 | 0.12.6 |
go/github.com/hashicorp/nomad | >=0.11.0<0.11.5 | 0.11.5 |
go/github.com/hashicorp/nomad | >=0.9.0<0.10.6 | 0.10.6 |
HashiCorp Nomad | >=0.9.0<=0.10.5 | |
HashiCorp Nomad | >=0.9.0<=0.10.5 | |
HashiCorp Nomad | >=0.11.0<=0.11.4 | |
HashiCorp Nomad | >=0.11.0<=0.11.4 | |
HashiCorp Nomad | >=0.12.0<=0.12.5 | |
HashiCorp Nomad | >=0.12.0<=0.12.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this HashiCorp Nomad vulnerability is CVE-2020-27195.
The severity of CVE-2020-27195 is critical with a CVSS score of 9.1.
The affected software versions for CVE-2020-27195 range from 0.9.0 up to 0.12.5 for HashiCorp Nomad and Nomad Enterprise.
The client file sandbox feature can be subverted in HashiCorp Nomad and Nomad Enterprise using either the template or artifact stanzas.
You can fix CVE-2020-27195 by updating to version 0.12.6, 0.11.5, or 0.10.6 of HashiCorp Nomad or Nomad Enterprise.