HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.
References
Configurations
Configuration 1 (hide)
|
History
02 Jan 2026, 20:23
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://discuss.hashicorp.com/t/hcsec-2024-15-nomad-vulnerable-to-allocation-directory-path-escape-through-archive-unpacking/68781 - Vendor Advisory | |
| CPE | cpe:2.3:a:hashicorp:nomad:1.8.1:*:*:*:-:*:*:* cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:* cpe:2.3:a:hashicorp:nomad:1.8.1:*:*:*:enterprise:*:*:* cpe:2.3:a:hashicorp:nomad:1.6.12:*:*:*:-:*:*:* cpe:2.3:a:hashicorp:nomad:1.6.12:*:*:*:enterprise:*:*:* cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:* |
|
| First Time |
Hashicorp
Hashicorp nomad |
21 Nov 2024, 09:50
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://discuss.hashicorp.com/t/hcsec-2024-15-nomad-vulnerable-to-allocation-directory-path-escape-through-archive-unpacking/68781 - |
24 Jul 2024, 12:55
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
23 Jul 2024, 01:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-07-23 01:15
Updated : 2026-01-02 20:23
NVD link : CVE-2024-6717
Mitre link : CVE-2024-6717
CVE.ORG link : CVE-2024-6717
JSON object : View
Products Affected
hashicorp
- nomad
CWE
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
