<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Nomad</title>
  <link>https://cvedaily.com/pages/tags/nomad.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/nomad.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Nomad</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:48 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-8052 – HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8052</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8052</guid>
    <pubDate>Tue, 12 May 2026 20:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-8052</strong></p>
  <p>HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2 task driver.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8052">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7474 – HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7474</guid>
    <pubDate>Tue, 12 May 2026 20:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7474</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6959 – HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6959</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6959</guid>
    <pubDate>Tue, 12 May 2026 20:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6959</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6959">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-62328 – HCL Nomad server on Domino did not configure the frame-ancestors directive in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62328</guid>
    <pubDate>Wed, 11 Mar 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-62328</strong></p>
  <p>HCL Nomad server on Domino did not configure the frame-ancestors directive in the Content-Security-Policy header by default which could allow an attacker to obtain sensitive information via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-1021</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23571 – A command injection vulnerability was discovered in TeamViewer DEX (former 1E DE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23571</guid>
    <pubDate>Thu, 29 Jan 2026 09:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23571</strong></p>
  <p>A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction. Improper input validation allows authenticated attackers with actioner privilege to run elevated arbitrary commands on connected hosts via malicious commands injected into the instruction’s input field. Users of 1E Client version 24.5 or higher are…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-23566 – A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distributi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23566</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23566</guid>
    <pubDate>Thu, 29 Jan 2026 09:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-23566</strong></p>
  <p>A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to inject, tamper with, or forge log entries in \Nomad Branch.log via crafted data sent to the UDP network handler. This can impact log integrity and nonrepudiation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23566">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64994 – A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64994</guid>
    <pubDate>Thu, 11 Dec 2025 12:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64994</strong></p>
  <p>A privilege escalation vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-SetWorkRate instruction prior V17.1. The improper handling of executable search paths could allow local attackers with write access to a PATH directory on a device to escalate privileges and execute arbitrary code as SYSTEM.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64992 – A command injection vulnerability was discovered in TeamViewer DEX (former 1E DE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64992</guid>
    <pubDate>Thu, 11 Dec 2025 12:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64992</strong></p>
  <p>A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-PauseNomadJobQueue instruction prior V25. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64988 – A command injection vulnerability was discovered in TeamViewer DEX (former 1E DE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64988</guid>
    <pubDate>Thu, 11 Dec 2025 12:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64988</strong></p>
  <p>A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-GetCmContentLocations instruction prior V19.2. Improper input validation, allowing authenticated attackers with Actioner privileges to inject arbitrary commands. Exploitation enables remote execution of elevated commands on devices connected to the platform.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-44016 – A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distributi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-44016</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-44016</guid>
    <pubDate>Thu, 11 Dec 2025 12:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-44016</strong></p>
  <p>A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file integrity validation via a crafted request. By providing a valid hash for a malicious file, an attacker can cause the service to incorrectly validate and process the file as trusted, enabling arbitrary code execution un…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-44016">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63205 – An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedd...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63205</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63205</guid>
    <pubDate>Wed, 19 Nov 2025 18:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63205</strong></p>
  <p>An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Probe, VB440 ST 2110 Production Analytics Probe, and NOMAD, firmware versions 6.5.0-9, allowing attackers to gain sensitive information such as administrator passwords via the /probe/core/setup/passwd endpoint. NOTE: the Supplier disagrees that 6.5.0-9 is affected, and instead rep…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63205">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4922 – Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4922</guid>
    <pubDate>Wed, 11 Jun 2025 14:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4922</strong></p>
  <p>Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3744 – Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3744</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3744</guid>
    <pubDate>Tue, 13 May 2025 19:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3744</strong></p>
  <p>Nomad Enterprise (“Nomad”) jobs using the policy override option are bypassing the mandatory sentinel policies. This vulnerability, identified as CVE-2025-3744, is fixed in Nomad Enterprise 1.10.1, 1.9.9, and 1.8.13.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3744">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32409 – Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32409</guid>
    <pubDate>Mon, 07 Apr 2025 22:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32409</strong></p>
  <p>Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of both directory traversal and unintended handling of concurrency.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1683 – Improper link resolution before file access in the Nomad module of the 1E Client...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1683</guid>
    <pubDate>Wed, 12 Mar 2025 16:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1683</strong></p>
  <p>Improper link resolution before file access in the Nomad module of the 1E Client, in versions prior to 25.3, enables an attacker with local unprivileged access on a Windows system to delete arbitrary files on the device by exploiting symbolic links.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-1296 – Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1296</guid>
    <pubDate>Mon, 10 Mar 2025 18:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-1296</strong></p>
  <p>Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0937 – Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0937</guid>
    <pubDate>Wed, 12 Feb 2025 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0937</strong></p>
  <p>Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-12678 – Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-12678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-12678</guid>
    <pubDate>Fri, 20 Dec 2024 02:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-12678</strong></p>
  <p>Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace through unredacted workload identity tokens. This vulnerability, identified as CVE-2024-12678, is fixed in Nomad Community Edition 1.9.4 and Nomad Enterprise 1.9.4, 1.8.8, and 1.7.16.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-10975 – Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerabl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-10975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-10975</guid>
    <pubDate>Thu, 07 Nov 2024 21:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-10975</strong></p>
  <p>Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, identified as CVE-2024-10975, is fixed in Nomad Community Edition 1.9.2 and Nomad Enterprise 1.9.2, 1.8.7, and 1.7.15.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-10975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-30132 – HCL Nomad server on Domino did not configure certain HTTP Security headers by de...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30132</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30132</guid>
    <pubDate>Tue, 01 Oct 2024 12:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-30132</strong></p>
  <p>HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30132">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-23586 – HCL Nomad is susceptible to an insufficient session expiration vulnerability.   ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23586</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23586</guid>
    <pubDate>Fri, 27 Sep 2024 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-23586</strong></p>
  <p>HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23586">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-30128 – HCL Nomad server on Domino is affected by an open proxy vulnerability in which a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30128</guid>
    <pubDate>Wed, 25 Sep 2024 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-30128</strong></p>
  <p>HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address.  This may enable an attacker to trick the user into exposing sensitive information.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-441</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-7625 – In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7625</guid>
    <pubDate>Thu, 15 Aug 2024 00:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-7625</strong></p>
  <p>In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-6717 – HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6717</guid>
    <pubDate>Tue, 23 Jul 2024 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-6717</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-30130 – HCL Nomad server on Domino is vulnerable to the cache containing sensitive infor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30130</guid>
    <pubDate>Fri, 19 Jul 2024 02:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-30130</strong></p>
  <p>HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive information.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-525</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-23588 – HCL Nomad server on Domino fails to properly handle users configured with limite...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23588</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23588</guid>
    <pubDate>Fri, 05 Jul 2024 14:15:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-23588</strong></p>
  <p>HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23588">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-1378 – A command injection vulnerability was identified in GitHub Enterprise Server tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1378</guid>
    <pubDate>Tue, 13 Feb 2024 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-1378</strong></p>
  <p>A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring SMTP options. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vu…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-1374 – A command injection vulnerability was identified in GitHub Enterprise Server tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1374</guid>
    <pubDate>Tue, 13 Feb 2024 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-1374</strong></p>
  <p>A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring audit log forwarding. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role.…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1329 – HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template rend...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1329</guid>
    <pubDate>Thu, 08 Feb 2024 20:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1329</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. This vulnerability, CVE-2024-1329, is fixed in Nomad 1.7.4, 1.6.7, and 1.5.14.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-3300 – HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search AP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3300</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3300</guid>
    <pubDate>Thu, 20 Jul 2023 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-3300</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. Fixed in 1.6.0, 1.5.7, and 1.4.1.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3300">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-3299 – HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3299</guid>
    <pubDate>Thu, 20 Jul 2023 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-3299</strong></p>
  <p>HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.</p>
  <p><strong>CVSS:</strong> 3.4 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-3072 – HashiCorp Nomad and Nomad Enterprise 0.7.0 up to 1.5.6 and 1.4.10 ACL policies u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-3072</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-3072</guid>
    <pubDate>Thu, 20 Jul 2023 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-3072</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 0.7.0 up to 1.5.6 and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-3072">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-1782 – HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-1782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-1782</guid>
    <pubDate>Wed, 05 Apr 2023 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-1782</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise versions 1.5.0 up to 1.5.2 allow unauthenticated users to bypass intended ACL authorizations for clusters where mTLS is not enabled. This issue is fixed in version 1.5.3.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-1299 – HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-1299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-1299</guid>
    <pubDate>Tue, 14 Mar 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-1299</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 1.5.0 allow a job submitter to escalate to management-level privileges using workload identity and task API. Fixed in 1.5.1.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-1296 – HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-1296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-1296</guid>
    <pubDate>Tue, 14 Mar 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-1296</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and 1.5.1.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-682</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-1296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-34910 – An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Androi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34910</guid>
    <pubDate>Mon, 27 Feb 2023 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-34910</strong></p>
  <p>An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a local database to store data and accounts. However, the password is stored in cleartext. Therefore, an attacker can retrieve the passwords of other users that used the same device.</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34909 – An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Androi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34909</guid>
    <pubDate>Mon, 27 Feb 2023 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34909</strong></p>
  <p>An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It allows SQL Injection, by which an attacker can bypass authentication and retrieve data that is stored in the database.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-34908 – An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Androi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34908</guid>
    <pubDate>Mon, 27 Feb 2023 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-34908</strong></p>
  <p>An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features do not require any token or cookie in a request. Therefore, an attacker may send a simple HTTP request to the right endpoint, and obtain authorization to retrieve application data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0821 – HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0821</guid>
    <pubDate>Thu, 16 Feb 2023 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0821</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-409</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-14802 – HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-14802</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-14802</guid>
    <pubDate>Mon, 26 Dec 2022 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-14802</strong></p>
  <p>HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applies to nomad/client/allocrunner/taskrunner/template.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-14802">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2022-3867 – HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3867</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3867</guid>
    <pubDate>Thu, 10 Nov 2022 06:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2022-3867</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-613</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3867">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-3866 – HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-3866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-3866</guid>
    <pubDate>Thu, 10 Nov 2022 06:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-3866</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-41606 – HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41606</guid>
    <pubDate>Wed, 12 Oct 2022 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-41606</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-30324 – HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-30324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-30324</guid>
    <pubDate>Thu, 02 Jun 2022 14:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-30324</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24685 – HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24685</guid>
    <pubDate>Mon, 28 Feb 2022 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24685</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fixed in 1.0.18, 1.1.12, and 1.2.6.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24683 – HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24683</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24683</guid>
    <pubDate>Thu, 17 Feb 2022 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24683</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24683">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-24684 – HashiCorp Nomad and Nomad Enterprise 0.9.0 through 1.0.16, 1.1.11, and 1.2.5 all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24684</guid>
    <pubDate>Tue, 15 Feb 2022 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-24684</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 0.9.0 through 1.0.16, 1.1.11, and 1.2.5 allow operators with job-submit capabilities to use the spread stanza to panic server agents. Fixed in 1.0.18, 1.1.12, and 1.2.6.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24684">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-24686 – HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 art...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24686</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24686</guid>
    <pubDate>Mon, 14 Feb 2022 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-24686</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destination. Fixed in 1.0.18, 1.1.12, and 1.2.6</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24686">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-43415 – HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QE...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43415</guid>
    <pubDate>Fri, 03 Dec 2021 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-43415</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-41865 – HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41865</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41865</guid>
    <pubDate>Thu, 07 Oct 2021 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-41865</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by submitting incomplete job specifications with a Consul mesh gateway and host networking mode. Fixed in 1.1.6.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41865">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37218 – HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37218</guid>
    <pubDate>Tue, 07 Sep 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37218</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21681 – Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21681</guid>
    <pubDate>Tue, 31 Aug 2021 14:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21681</strong></p>
  <p>Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-32575 – HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32575</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32575</guid>
    <pubDate>Thu, 17 Jun 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-32575</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged tasks on the same node. Fixed in 0.12.12, 1.0.5, and 1.1.0 RC1.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32575">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3283 – HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3283</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3283</guid>
    <pubDate>Mon, 01 Feb 2021 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3283</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can access processes associated with other tasks on the same node. Fixed in 0.12.10, and 1.0.3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3283">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-16268 – The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-16268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-16268</guid>
    <pubDate>Tue, 29 Dec 2020 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-16268</strong></p>
  <p>The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair option. This applies to installations that have a TRANSFORM (MST) with the option to disable the installation of the Nomad module. An attacker may craft a .reg file in a specific location that will be able to write to any registry key as an elevated u…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-16268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-28348 – HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandb...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28348</guid>
    <pubDate>Tue, 24 Nov 2020 03:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-28348</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandbox feature may be subverted when not explicitly disabled or when using a volume mount type. Fixed in 0.12.8, 0.11.7, and 0.10.8.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-27195 – HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sand...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-27195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-27195</guid>
    <pubDate>Thu, 22 Oct 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-27195</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-27195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-4092 – "If port encryption is not enabled on the Domino Server, HCL Nomad on Android an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4092</guid>
    <pubDate>Wed, 06 May 2020 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-4092</strong></p>
  <p>"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can potentially expose sensitive information including but not limited to server names, user IDs and document content."</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-10944 – HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10944</guid>
    <pubDate>Tue, 28 Apr 2020 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-10944</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could cause arbitrary JavaScript to execute in the web UI. Fixed in 0.10.5.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-7956 – HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/reg...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7956</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7956</guid>
    <pubDate>Fri, 31 Jan 2020 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-7956</strong></p>
  <p>HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7956">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7218 – HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7218</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7218</guid>
    <pubDate>Fri, 31 Jan 2020 13:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7218</strong></p>
  <p>HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 0.10.3.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7218">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-12618 – HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec dr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12618</guid>
    <pubDate>Mon, 12 Aug 2019 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-12618</strong></p>
  <p>HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-1003093 – A missing permission check in Jenkins Nomad Plugin in the NomadCloud.DescriptorI...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-1003093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-1003093</guid>
    <pubDate>Thu, 04 Apr 2019 16:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-1003093</strong></p>
  <p>A missing permission check in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1003093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-1003092 – A cross-site request forgery vulnerability in Jenkins Nomad Plugin in the NomadC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-1003092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-1003092</guid>
    <pubDate>Thu, 04 Apr 2019 16:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-1003092</strong></p>
  <p>A cross-site request forgery vulnerability in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1003092">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
