6.5
CVSSv3

CVE-2020-28348

Published: 24/11/2020 Updated: 04/12/2020
CVSS v2 Base Score: 6.3 | Impact Score: 6.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 561
Vector: AV:N/AC:M/Au:S/C:C/I:N/A:N

Vulnerability Summary

HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandbox feature may be subverted when not explicitly disabled or when using a volume mount type. Fixed in 0.12.8, 0.11.7, and 0.10.8.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hashicorp nomad

Vendor Advisories

Debian Bug report logs - #976593 nomad: CVE-2020-28348 Package: src:nomad; Maintainer for src:nomad is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 5 Dec 2020 15:42:02 UTC Severity: important Tags: security, upstream Found in version nomad/0105+dfsg1-3 F ...