CVE-2023-0821Improper Handling of Highly Compressed Data (Data Amplification) in Hashicorp Nomad

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 36.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 16
Latest updateAug 20

Description

HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5hashicorp/nomad_enterprise1.2.15+2
NVDhashicorp/nomad1.3.01.3.9+2
Gogithub.com/hashicorp_nomad1.2.151.2.16+2
CVEListV5hashicorp/nomad1.2.15+2

🔴Vulnerability Details

5
OSV
Uncontrolled Resource Consumption in Hashicorp Nomad in github.com/hashicorp/nomad2024-08-20
OSV
Uncontrolled Resource Consumption in Hashicorp Nomad2023-02-17
GHSA
Uncontrolled Resource Consumption in Hashicorp Nomad2023-02-17
OSV
CVE-2023-0821: HashiCorp Nomad and Nomad Enterprise 12023-02-16
CVEList
Nomad Client Vulnerable to Decompression Bombs in Artifact Block2023-02-16

📋Vendor Advisories

1
Red Hat
hashicorp/nomad: Nomad Client Vulnerable to Decompression Bombs in Artifact Block2023-02-17
CVE-2023-0821 — Hashicorp Nomad vulnerability | cvebase