In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability.
References
Configurations
No configuration.
History
25 Sep 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
Summary | (en) In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability. |
15 Aug 2024, 00:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-15 00:15
Updated : 2024-09-25 16:15
NVD link : CVE-2024-7625
Mitre link : CVE-2024-7625
CVE.ORG link : CVE-2024-7625
JSON object : View
Products Affected
No product.
CWE
CWE-610
Externally Controlled Reference to a Resource in Another Sphere