Related Vulnerabilities: CVE-2021-41865  

HashiCorp Nomad 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by submitting incomplete job specifications with a Consul mesh gateway and host networking mode.

Severity Low

Remote Yes

Type Denial of service

Description

HashiCorp Nomad 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by submitting incomplete job specifications with a Consul mesh gateway and host networking mode.

AVG-2451 nomad 1.1.5-1 1.1.6-1 Low Fixed

https://discuss.hashicorp.com/t/hcsec-2021-26-nomad-denial-of-service-via-submission-of-incomplete-job-specification-using-consul-mesh-gateway-host-network/30311
https://github.com/hashicorp/nomad/pull/11257
https://github.com/hashicorp/nomad/commit/3c1aaf9b7c8af3abd330d92ad724f16b6c5c9d60