Use After Free in HashiCorp Nomad
Critical severity
GitHub Reviewed
Published
Feb 15, 2022
to the GitHub Advisory Database
•
Updated Oct 2, 2023
Package
Affected versions
>= 0.9.0, < 0.10.6
>= 0.11.0, < 0.11.5
>= 0.12.0, < 0.12.6
Patched versions
0.10.6
0.11.5
0.12.6
Description
Reviewed
May 12, 2021
Published to the GitHub Advisory Database
Feb 15, 2022
Last updated
Oct 2, 2023
HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6
References