6.5
CVSSv3

CVE-2022-41606

Published: 12/10/2022 Updated: 13/10/2022
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hashicorp nomad

Vendor Advisories

Debian Bug report logs - #1021670 nomad: CVE-2022-41606 Package: src:nomad; Maintainer for src:nomad is Dmitry Smirnov <onlyjob@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 12 Oct 2022 17:45:02 UTC Severity: important Tags: security, upstream Reply or subscribe to this bug Toggle us ...