8.8
CVSSv3

CVE-2021-43415

Published: 03/12/2021 Updated: 08/08/2023
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hashicorp nomad

hashicorp nomad 1.2.0

Vendor Advisories

Debian Bug report logs - #1021273 nomad: CVE-2021-37218 CVE-2021-43415 CVE-2022-24683 CVE-2022-24684 CVE-2022-24685 CVE-2022-24686 Package: src:nomad; Maintainer for src:nomad is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Tue, 4 Oct 2022 19:45:04 UTC Severity: grave T ...
Nomad before version 121 with the QEMU task driver enabled allowed authenticated users with job submission capabilities to bypass the configured allowed paths for images ...