CVE-2022-41606: Input Validation
HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/hashicorp/nomadto a version that resolves this vulnerability.Fixed in 1.3.6 - Upgrade
Upgrade
go/github.com/hashicorp/nomadto a version that resolves this vulnerability.Fixed in 1.2.13 - Upgrade
Upgrade
HashiCorp Nomad (and Nomad Enterprise)to a version that resolves this vulnerability.Fixed in 1.2.13 - Upgrade
Upgrade
HashiCorp Nomad (and Nomad Enterprise)to a version that resolves this vulnerability.Fixed in 1.3.6 - Upgrade
Upgrade
HashiCorp Nomad (and Nomad Enterprise)to a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
What is the vulnerability ID of this Nomad issue?
The vulnerability ID of this Nomad issue is CVE-2022-41606.
What is the severity of CVE-2022-41606?
The severity of CVE-2022-41606 is medium.
Which versions of HashiCorp Nomad and Nomad Enterprise are affected by CVE-2022-41606?
HashiCorp Nomad and Nomad Enterprise versions 1.0.2 up to 1.2.12 and 1.3.0 up to 1.3.6 are affected by CVE-2022-41606.
How can this vulnerability be exploited?
This vulnerability can be exploited by submitting jobs with an artifact stanza using invalid S3 or GCS URLs, causing client agents to crash.
How can I fix CVE-2022-41606?
To fix CVE-2022-41606, update to version 1.2.13, 1.3.6, or 1.4.0 of HashiCorp Nomad or Nomad Enterprise.