CVE-2022-24683Path Traversal in Hashicorp Nomad

CWE-22Path Traversal6 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.5%
top 35.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 17
Latest updateAug 21

Description

HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDhashicorp/nomad0.9.21.0.18+2
Gogithub.com/hashicorp_nomad0.9.21.0.18+2

🔴Vulnerability Details

5
OSV
Arbitrary file reads in HashiCorp Nomad in github.com/hashicorp/nomad2024-08-21
GHSA
Arbitrary file reads in HashiCorp Nomad2022-02-18
OSV
Arbitrary file reads in HashiCorp Nomad2022-02-18
OSV
CVE-2022-24683: HashiCorp Nomad and Nomad Enterprise 02022-02-17
CVEList
CVE-2022-24683: HashiCorp Nomad and Nomad Enterprise 02022-02-17
CVE-2022-24683 — Path Traversal in Hashicorp Nomad | cvebase