PT-2026-56556 · Hashicorp · Nomad Community Edition+1
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Nomad Community Edition versions prior to 2.0.4
Nomad Enterprise versions prior to 2.0.4
Nomad Enterprise versions prior to 1.11.8
Nomad Enterprise versions prior to 1.10.14
Description
A sandbox escape exists in the Docker task driver. This issue allows a job submitter to bind-mount a host path into a container, bypassing restrictions even when volume bind mounts are disabled. This could enable an attacker to read and write files directly on the host system.
Recommendations
Update Nomad Community Edition to version 2.0.4.
Update Nomad Enterprise to version 2.0.4, 1.11.8, or 1.10.14.
Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nomad Community Edition
Nomad Enterprise