HashiCorp Nomad vulnerable to symlink attacks
High severity
GitHub Reviewed
Published
Feb 8, 2024
to the GitHub Advisory Database
•
Updated Sep 26, 2024
Package
Affected versions
= 1.5.13
>= 1.6.0, <= 1.6.6
= 1.7.3
Patched versions
1.5.14
1.6.7
1.7.4
Description
Published by the National Vulnerability Database
Feb 8, 2024
Published to the GitHub Advisory Database
Feb 8, 2024
Reviewed
Feb 9, 2024
Last updated
Sep 26, 2024
HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. Fixed in Nomad 1.7.4, 1.6.7, 1.5.14.
References