In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-08-15 00:15
Updated : 2024-09-25 16:15
NVD link : CVE-2024-7625
Mitre link : CVE-2024-7625
CVE.ORG link : CVE-2024-7625
JSON object : View
Products Affected
No product.
CWE
CWE-610
Externally Controlled Reference to a Resource in Another Sphere