CVE-2022-24685Allocation of Resources Without Limits or Throttling in Hashicorp Nomad

Severity
7.5HIGHNVD
EPSS
0.7%
top 28.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 28
Latest updateAug 21

Description

HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fixed in 1.0.18, 1.1.12, and 1.2.6.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDhashicorp/nomad1.1.01.1.12+2
Gogithub.com/hashicorp_nomad1.0.01.0.17+2

🔴Vulnerability Details

5
OSV
HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling in github.com/hashicorp/nomad2024-08-21
OSV
HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling2022-03-01
GHSA
HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling2022-03-01
OSV
CVE-2022-24685: HashiCorp Nomad and Nomad Enterprise 12022-02-28
CVEList
CVE-2022-24685: HashiCorp Nomad and Nomad Enterprise 12022-02-28
CVE-2022-24685 — Hashicorp Nomad vulnerability | cvebase