CVE-2021-3283: High severity HashiCorp Nomad vulnerability
HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can access processes associated with other tasks on the same node. Fixed in 0.12.10, and 1.0.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 0.12.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.0.3
Event History
Frequently Asked Questions
What is the vulnerability ID for this HashiCorp Nomad issue?
The vulnerability ID for this HashiCorp Nomad issue is CVE-2021-3283.
What is the severity of CVE-2021-3283?
The severity of CVE-2021-3283 is high with a severity value of 7.5.
How can HashiCorp Nomad and Nomad Enterprise version up to 0.12.9 be affected by this vulnerability?
HashiCorp Nomad and Nomad Enterprise versions up to 0.12.9 can be affected by this vulnerability if they are using the exec and java task drivers, as these drivers can access processes associated with other tasks on the same node.
Which versions of HashiCorp Nomad and Nomad Enterprise are fixed for this vulnerability?
This vulnerability is fixed in HashiCorp Nomad version 0.12.10 and Nomad Enterprise version 0.12.10, as well as Nomad version 1.0.3 and Nomad Enterprise version 1.0.3.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the HashiCorp discussion forum at the following link: [https://discuss.hashicorp.com/t/hcsec-2021-01-nomad-s-exec-and-java-task-drivers-did-not-isolate-processes/20332](https://discuss.hashicorp.com/t/hcsec-2021-01-nomad-s-exec-and-java-task-drivers-did-not-isolate-processes/20332)