CVE-2024-1329: Nomad Vulnerable to Arbitrary Write Through Symlink Attack
HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. Fixed in Nomad 1.7.4, 1.6.7, 1.5.14.
Other sources
HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. This vulnerability, CVE-2024-1329, is fixed in Nomad 1.7.4, 1.6.7, and 1.5.14.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/hashicorp/nomadto a version that resolves this vulnerability.Fixed in 1.7.4 - Upgrade
Upgrade
go/github.com/hashicorp/nomadto a version that resolves this vulnerability.Fixed in 1.6.7 - Upgrade
Upgrade
go/github.com/hashicorp/nomadto a version that resolves this vulnerability.Fixed in 1.5.14 - Upgrade
Upgrade
HashiCorp Nomad and Nomad Enterpriseto a version that resolves this vulnerability.Fixed in 1.7.4 - Upgrade
Upgrade
HashiCorp Nomad and Nomad Enterpriseto a version that resolves this vulnerability.Fixed in 1.6.7 - Upgrade
Upgrade
HashiCorp Nomad and Nomad Enterpriseto a version that resolves this vulnerability.Fixed in 1.5.14
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1329?
CVE-2024-1329 has a high severity due to its potential for arbitrary file write vulnerabilities.
How do I fix CVE-2024-1329?
To fix CVE-2024-1329, upgrade HashiCorp Nomad to version 1.7.4, 1.6.7, or 1.5.14.
What versions of HashiCorp Nomad are affected by CVE-2024-1329?
Versions of HashiCorp Nomad from 1.5.13 up to 1.6.6, and 1.7.3 are affected by CVE-2024-1329.
What does CVE-2024-1329 exploit?
CVE-2024-1329 exploits symlink attacks that allow arbitrary file writes on the host as the Nomad client user.
Is HashiCorp Nomad Enterprise affected by CVE-2024-1329?
Yes, HashiCorp Nomad Enterprise versions 1.5.13 up to 1.6.6, and 1.7.3 are also affected by CVE-2024-1329.