7.8
CVSSv2

CVE-2022-24683

Published: 17/02/2022 Updated: 11/05/2022
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

HashiCorp Nomad and Nomad Enterprise 0.9.2 up to and including 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hashicorp nomad

Vendor Advisories

Debian Bug report logs - #1021273 nomad: CVE-2021-37218 CVE-2021-43415 CVE-2022-24683 CVE-2022-24684 CVE-2022-24685 CVE-2022-24686 Package: src:nomad; Maintainer for src:nomad is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Tue, 4 Oct 2022 19:45:04 UTC Severity: grave T ...