First published: Tue Nov 24 2020(Updated: )
HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandbox feature (github.com/hashicorp/nomad/drivers/docker) may be subverted when not explicitly disabled or when using a volume mount type. Fixed in 0.12.8, 0.11.7, and 0.10.8.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/hashicorp/nomad | >=0.12.0-beta1<0.12.8 | 0.12.8 |
go/github.com/hashicorp/nomad | >=0.11.0-beta1<0.11.7 | 0.11.7 |
go/github.com/hashicorp/nomad | >=0.9.0<0.10.8 | 0.10.8 |
HashiCorp Nomad | >=0.9.0<0.10.8 | |
HashiCorp Nomad | >=0.11.0<0.11.7 | |
HashiCorp Nomad | >=0.12.0<0.12.8 | |
HashiCorp Nomad | >=0.9.0<0.10.8 | |
HashiCorp Nomad | >=0.11.0<0.11.7 | |
HashiCorp Nomad | >=0.12.0<0.12.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-28348.
The severity rating of CVE-2020-28348 is medium (6.5).
The Nomad client Docker file sandbox feature can be subverted when not explicitly disabled or when using a volume mount type.
HashiCorp Nomad and Nomad Enterprise versions 0.9.0 up to 0.12.7 are affected.
You can fix the vulnerability by updating to version 0.12.8, 0.11.7, or 0.10.8 of HashiCorp Nomad, depending on your current version.