Lucene search

K
cveMitreCVE-2022-24683
HistoryFeb 17, 2022 - 5:15 p.m.

CVE-2022-24683

2022-02-1717:15:09
mitre
web.nvd.nist.gov
111
2
cve-2022-24683
hashicorp
nomad
nomad enterprise
security vulnerability
arbitrary file read
root access
nvd

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.002

Percentile

55.5%

HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.

Affected configurations

Nvd
Node
hashicorpnomadRange0.9.21.0.18-
OR
hashicorpnomadRange0.9.21.0.18enterprise
OR
hashicorpnomadRange1.1.01.1.12-
OR
hashicorpnomadRange1.1.01.1.12enterprise
OR
hashicorpnomadRange1.2.01.2.6-
OR
hashicorpnomadRange1.2.01.2.6enterprise
VendorProductVersionCPE
hashicorpnomad*cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*
hashicorpnomad*cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*

Social References

More

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.002

Percentile

55.5%