6.4
CVSSv2

CVE-2020-27195

Published: 22/10/2020 Updated: 02/11/2020
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hashicorp nomad

Vendor Advisories

Debian Bug report logs - #972795 nomad: CVE-2020-27195: Nomad File Sandbox Escape via Template and Artifact Stanzas Package: src:nomad; Maintainer for src:nomad is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 23 Oct 2020 20:18:02 UTC Severity: important Tags: f ...