CVE-2020-28348Path Traversal in Hashicorp Nomad

CWE-22Path Traversal5 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.5%
top 34.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 24
Latest updateAug 21

Description

HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandbox feature may be subverted when not explicitly disabled or when using a volume mount type. Fixed in 0.12.8, 0.11.7, and 0.10.8.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDhashicorp/nomad0.9.00.10.8+2
Gogithub.com/hashicorp_nomad0.9.00.10.8+2

🔴Vulnerability Details

4
OSV
Path Traversal in HashiCorp Nomad in github.com/hashicorp/nomad2024-08-21
GHSA
Path Traversal in HashiCorp Nomad2022-02-15
OSV
Path Traversal in HashiCorp Nomad2022-02-15
CVEList
CVE-2020-28348: HashiCorp Nomad and Nomad Enterprise 02020-11-24
CVE-2020-28348 — Path Traversal in Hashicorp Nomad | cvebase