CVE-2020-27195Use After Free in Hashicorp Nomad

Severity
9.1CRITICALNVD
EPSS
0.4%
top 41.76%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 22
Latest updateAug 21

Description

HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

Gogithub.com/hashicorp_nomad0.9.00.10.6+2
NVDhashicorp/nomad0.9.00.10.5+2

🔴Vulnerability Details

5
OSV
Use After Free in HashiCorp Nomad in github.com/hashicorp/nomad2024-08-21
GHSA
Use After Free in HashiCorp Nomad2022-02-15
OSV
Use After Free in HashiCorp Nomad2022-02-15
CVEList
CVE-2020-27195: HashiCorp Nomad and Nomad Enterprise version 02020-10-22
OSV
CVE-2020-27195: HashiCorp Nomad and Nomad Enterprise version 02020-10-22

📋Vendor Advisories

1
Red Hat
nomad: file sandbox escape via template and artifact stanzas2020-10-21

💬Community

1
Bugzilla
CVE-2020-27195 nomad: file sandbox escape via template and artifact stanzas2020-10-29
CVE-2020-27195 — Use After Free in Hashicorp Nomad | cvebase