<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Nomad (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/nomad.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/nomad-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Nomad (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-7474 – HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7474</guid>
    <pubDate>Tue, 12 May 2026 20:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7474</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64988 – A command injection vulnerability was discovered in TeamViewer DEX (former 1E DE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64988</guid>
    <pubDate>Thu, 11 Dec 2025 12:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64988</strong></p>
  <p>A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-GetCmContentLocations instruction prior V19.2. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-44016 – A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distributi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-44016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-44016</guid>
    <pubDate>Thu, 11 Dec 2025 12:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-44016</strong></p>
  <p>A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file integrity validation via a crafted request. By providing a valid hash for a malicious file, an attacker can cause the service to incorrectly validate and process the file as trusted, enabling arbitrary code execution un…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-44016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63205 – An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedd...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63205</guid>
    <pubDate>Wed, 19 Nov 2025 18:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63205</strong></p>
  <p>An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production Analytics Probe, and NOMAD, firmware versions 6.5.0-9, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint. NOTE: the Supplier disagrees that 6.5.0-9 is affected, and instead rep…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4922 – Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4922</guid>
    <pubDate>Wed, 11 Jun 2025 14:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4922</strong></p>
  <p>Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3744 – Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3744</guid>
    <pubDate>Tue, 13 May 2025 19:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3744</strong></p>
  <p>Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32409 – Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32409</guid>
    <pubDate>Mon, 07 Apr 2025 22:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32409</strong></p>
  <p>Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurrency.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1683 – Improper link resolution before file access in the Nomad module of the 1E Client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1683</guid>
    <pubDate>Wed, 12 Mar 2025 16:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1683</strong></p>
  <p>Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by exploiting symbolic links.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0937 – Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0937</guid>
    <pubDate>Wed, 12 Feb 2025 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0937</strong></p>
  <p>Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-10975 – Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10975</guid>
    <pubDate>Thu, 07 Nov 2024 21:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-10975</strong></p>
  <p>Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, identified as CVE-2024-10975, is fixed in Nomad Community Edition 1.9.2 and Nomad Enterprise 1.9.2, 1.8.7, and 1.7.15.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-30128 – HCL Nomad server on Domino is affected by an open proxy vulnerability in which a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30128</guid>
    <pubDate>Wed, 25 Sep 2024 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-30128</strong></p>
  <p>HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address.  This may enable an attacker to trick the user into exposing sensitive information.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-441</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-6717 – HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6717</guid>
    <pubDate>Tue, 23 Jul 2024 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-6717</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-1378 – A command injection vulnerability was identified in GitHub Enterprise Server tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1378</guid>
    <pubDate>Tue, 13 Feb 2024 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-1378</strong></p>
  <p>A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring SMTP options. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vu…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-1374 – A command injection vulnerability was identified in GitHub Enterprise Server tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1374</guid>
    <pubDate>Tue, 13 Feb 2024 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-1374</strong></p>
  <p>A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring audit log forwarding. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role.…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1329 – HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template rend...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1329</guid>
    <pubDate>Thu, 08 Feb 2024 20:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1329</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. This vulnerability, CVE-2024-1329, is fixed in Nomad 1.7.4, 1.6.7, and 1.5.14.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-1782 – HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-1782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-1782</guid>
    <pubDate>Wed, 05 Apr 2023 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-1782</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-1299 – HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-1299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-1299</guid>
    <pubDate>Tue, 14 Mar 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-1299</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fixed in 1.5.1.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34909 – An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Androi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34909</guid>
    <pubDate>Mon, 27 Feb 2023 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34909</strong></p>
  <p>An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It allows SQL Injection, by which an attacker can bypass authentication and retrieve data that is stored in the database.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34908 – An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Androi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34908</guid>
    <pubDate>Mon, 27 Feb 2023 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34908</strong></p>
  <p>An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features do not require any token or cookie in a request. Therefore, an attacker may send a simple HTTP request to the right endpoint, and obtain authorization to retrieve application data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-30324 – HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-30324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-30324</guid>
    <pubDate>Thu, 02 Jun 2022 14:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-30324</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24685 – HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24685</guid>
    <pubDate>Mon, 28 Feb 2022 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24685</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fixed in 1.0.18, 1.1.12, and 1.2.6.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24683 – HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24683</guid>
    <pubDate>Thu, 17 Feb 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24683</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43415 – HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43415</guid>
    <pubDate>Fri, 03 Dec 2021 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43415</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37218 – HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37218</guid>
    <pubDate>Tue, 07 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37218</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3283 – HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3283</guid>
    <pubDate>Mon, 01 Feb 2021 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3283</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can access processes associated with other tasks on the same node. Fixed in 0.12.10, and 1.0.3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3283">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-16268 – The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-16268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-16268</guid>
    <pubDate>Tue, 29 Dec 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-16268</strong></p>
  <p>The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair option. This applies to installations that have a TRANSFORM (MST) with the option to disable the installation of the Nomad module. An attacker may craft a .reg file in a specific location that will be able to write to any registry key as an elevated u…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-27195 – HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sand...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27195</guid>
    <pubDate>Thu, 22 Oct 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-27195</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7956 – HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/reg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7956</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7956</guid>
    <pubDate>Fri, 31 Jan 2020 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7956</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7956">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7218 – HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7218</guid>
    <pubDate>Fri, 31 Jan 2020 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7218</strong></p>
  <p>HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 0.10.3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-12618 – HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec dr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12618</guid>
    <pubDate>Mon, 12 Aug 2019 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-12618</strong></p>
  <p>HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12618">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
