CVE-2020-7218: High severity HashiCorp Nomad vulnerability
HashiCorp Nomad and Nomad Enterprise before 0.10.3 allow unbounded resource usage.
Specific Go Packages Affected github.com/hashicorp/nomad/command/agent
Other sources
HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 0.10.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/hashicorp/nomadto a version that resolves this vulnerability.Fixed in 0.10.3 - Upgrade
Upgrade
github.com/hashicorp/nomad/command/agentto a version that resolves this vulnerability.Fixed in 0.10.3
Event History
Frequently Asked Questions
What is the vulnerability ID of this security vulnerability?
The vulnerability ID of this security vulnerability is CVE-2020-7218.
What is the severity of CVE-2020-7218?
The severity of CVE-2020-7218 is high with a severity value of 7.5.
What is the affected software for CVE-2020-7218?
The affected software for CVE-2020-7218 is HashiCorp Nomad (up to 0.10.2) and Nomad Enterprise (up to 0.10.2).
How can I fix CVE-2020-7218?
To fix CVE-2020-7218, you need to update to version 0.10.3 of HashiCorp Nomad or Nomad Enterprise.
Where can I find more information about CVE-2020-7218?
You can find more information about CVE-2020-7218 on the NIST National Vulnerability Database (NVD) website and the HashiCorp Nomad GitHub repository.