CVE-2023-0821: Nomad Client Vulnerable to Decompression Bombs in Artifact Block
HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-0821?
CVE-2023-0821 is a vulnerability in HashiCorp Nomad and Nomad Enterprise versions 1.2.15 up to 1.3.8, and 1.4.3 that can cause excessive disk usage when jobs using a maliciously compressed artifact stanza source.
Is my version of HashiCorp Nomad affected?
If you are using HashiCorp Nomad or Nomad Enterprise versions 1.2.15 up to 1.3.8, and 1.4.3, you are affected by CVE-2023-0821.
What is the severity of CVE-2023-0821?
The severity of CVE-2023-0821 is rated as medium with a severity score of 6.5.
How can I fix CVE-2023-0821?
You can fix CVE-2023-0821 by upgrading to the patched versions: 1.2.16, 1.3.9, or 1.4.4.
Where can I find more information about CVE-2023-0821?
You can find more information about CVE-2023-0821 at the following reference: [link](https://discuss.hashicorp.com/t/hcsec-2023-05-nomad-client-vulnerable-to-decompression-bombs-in-artifact-block/50292)