CVE-2022-24683: High severity hashicorp nomad vulnerability
HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24683?
CVE-2022-24683 is a vulnerability that allows operators with certain capabilities to read arbitrary files on the host filesystem as root in HashiCorp Nomad and Nomad Enterprise versions 0.9.2 - 1.0.17, 1.1.11, and 1.2.5.
What is the severity of CVE-2022-24683?
CVE-2022-24683 has a severity rating of 7.5 (High).
How does CVE-2022-24683 affect HashiCorp Nomad and Nomad Enterprise?
CVE-2022-24683 affects HashiCorp Nomad and Nomad Enterprise versions 0.9.2 - 1.0.17, 1.1.11, and 1.2.5.
What capabilities allow the exploitation of CVE-2022-24683?
CVE-2022-24683 can be exploited by operators with read-fs and alloc-exec (or job-submit) capabilities.
How can I fix CVE-2022-24683?
To fix CVE-2022-24683, it is recommended to update HashiCorp Nomad and Nomad Enterprise to a version beyond 1.0.18, 1.1.12, or 1.2.6.