First published: Thu Feb 16 2023(Updated: )
HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4.
Credit: security@hashicorp.com
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Nomad | <1.2.15 | |
HashiCorp Nomad | <1.2.15 | |
HashiCorp Nomad | >=1.3.0<1.3.9 | |
HashiCorp Nomad | >=1.3.0<1.3.9 | |
HashiCorp Nomad | >=1.4.0<1.4.4 | |
HashiCorp Nomad | >=1.4.0<1.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0821 is a vulnerability in HashiCorp Nomad and Nomad Enterprise versions 1.2.15 up to 1.3.8, and 1.4.3 that can cause excessive disk usage when jobs using a maliciously compressed artifact stanza source.
If you are using HashiCorp Nomad or Nomad Enterprise versions 1.2.15 up to 1.3.8, and 1.4.3, you are affected by CVE-2023-0821.
The severity of CVE-2023-0821 is rated as medium with a severity score of 6.5.
You can fix CVE-2023-0821 by upgrading to the patched versions: 1.2.16, 1.3.9, or 1.4.4.
You can find more information about CVE-2023-0821 at the following reference: [link](https://discuss.hashicorp.com/t/hcsec-2023-05-nomad-client-vulnerable-to-decompression-bombs-in-artifact-block/50292)