Improper Privilege Management in HashiCorp Nomad
High severity
GitHub Reviewed
Published
Jun 24, 2021
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Package
Affected versions
>= 1.0.0, < 1.0.3
< 0.12.10
Patched versions
1.0.3
0.12.10
Description
Reviewed
May 12, 2021
Published to the GitHub Advisory Database
Jun 24, 2021
Last updated
Jan 9, 2023
HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can access processes associated with other tasks on the same node. Fixed in 0.12.10, and 1.0.3.
References