PT-2026-56533 · Hashicorp · Nomad+1
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nomad Community Edition versions prior to 2.0.4
Nomad Enterprise versions prior to 2.0.4
Nomad Enterprise versions prior to 1.11.8
Nomad Enterprise versions prior to 1.10.14
Description
HashiCorp Nomad and Nomad Enterprise failed to enforce the
allow privileged restriction for the Docker task driver's host namespace mode options. This flaw allows an authenticated job submitter to execute a container within a host namespace, potentially granting unauthorized access to information on the host or other workloads residing on the same client.Recommendations
Update Nomad Community Edition to version 2.0.4.
Update Nomad Enterprise to version 2.0.4, 1.11.8, or 1.10.14.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nomad
Nomad Enterprise