First published: Fri Dec 03 2021(Updated: )
HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Nomad | >=1.0.0<1.0.14 | |
HashiCorp Nomad | >=1.0.0<1.0.14 | |
HashiCorp Nomad | >=1.1.0<1.1.8 | |
HashiCorp Nomad | >=1.1.0<1.1.8 | |
HashiCorp Nomad | =1.2.0 | |
HashiCorp Nomad | =1.2.0 | |
>=1.0.0<1.0.14 | ||
>=1.0.0<1.0.14 | ||
>=1.1.0<1.1.8 | ||
>=1.1.0<1.1.8 | ||
=1.2.0 | ||
=1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43415 is a vulnerability in HashiCorp Nomad and Nomad Enterprise up to version 1.2.0 with the QEMU task driver enabled that allowed authenticated users to bypass configured allowed image paths.
CVE-2021-43415 is classified as a high severity vulnerability with a severity score of 8.8.
HashiCorp Nomad versions up to 1.0.13, 1.1.7, and 1.2.0 (including Nomad Enterprise) are affected.
To fix CVE-2021-43415, you should upgrade to HashiCorp Nomad versions 1.0.14, 1.1.8, or 1.2.1 (or the corresponding Nomad Enterprise versions).
You can find more information about CVE-2021-43415 on the HashiCorp forums and blog. - [HashiCorp Forum](https://discuss.hashicorp.com/t/hcsec-2021-31-nomad-qemu-task-driver-allowed-paths-bypass-with-job-args/32288) - [HashiCorp Blog](https://www.hashicorp.com/blog/category/nomad)