CVE-2022-30324: Critical severity hashicorp nomad vulnerability
Published May 27, 2022
·Updated
HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.
Affected Software
6 affected components
HashiCorp Nomad>=0.2.0<1.1.14
HashiCorp Nomad>=0.2.0<1.1.14
HashiCorp Nomad>=1.2.0<1.2.8
HashiCorp Nomad>=1.2.0<1.2.8
HashiCorp Nomad=1.3.0
HashiCorp Nomad=1.3.0
Event History
May 27, 2022
CVE Published
via MITRE·02:48 PM
Data Sourced
via MITRE·02:48 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this HashiCorp Nomad vulnerability?
The vulnerability ID for this HashiCorp Nomad vulnerability is CVE-2022-30324.
2
What is the severity of CVE-2022-30324?
The severity of CVE-2022-30324 is critical with a CVSS score of 9.8.
3
How can privilege escalation be achieved through the vulnerability?
Privilege escalation can be achieved through the artifact stanza in submitted jobs onto the client agent host.
4
Which versions of HashiCorp Nomad and Nomad Enterprise are affected by the vulnerability?
HashiCorp Nomad and Nomad Enterprise versions 0.2.0 up to 1.3.0 are affected by the vulnerability.
5
How can I fix CVE-2022-30324?
The vulnerability is fixed in HashiCorp Nomad versions 1.1.14, 1.2.8, and 1.3.1.