First published: Tue Oct 11 2022(Updated: )
HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Nomad | >=1.0.2<1.2.13 | |
HashiCorp Nomad | >=1.0.2<1.2.13 | |
HashiCorp Nomad | >=1.3.0<1.3.6 | |
HashiCorp Nomad | >=1.3.0<1.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Nomad issue is CVE-2022-41606.
The severity of CVE-2022-41606 is medium.
HashiCorp Nomad and Nomad Enterprise versions 1.0.2 up to 1.2.12 and 1.3.0 up to 1.3.6 are affected by CVE-2022-41606.
This vulnerability can be exploited by submitting jobs with an artifact stanza using invalid S3 or GCS URLs, causing client agents to crash.
To fix CVE-2022-41606, update to version 1.2.13, 1.3.6, or 1.4.0 of HashiCorp Nomad or Nomad Enterprise.