CVE-2024-1329
Nomad Vulnerable to Arbitrary Write Through Symlink Attack
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. Fixed in Nomad 1.7.4, 1.6.7, 1.5.14.
HashiCorp Nomad y Nomad Enterprise 1.5.13 hasta 1.6.6 y 1.7.3 el renderizador de plantillas es vulnerable a la escritura de archivos arbitrarios en el host como usuario del cliente Nomad a través de ataques de enlaces simbólicos. Corregido en Nomad 1.7.4, 1.6.7, 1.5.14.
HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. This vulnerability, CVE-2024-1329, is fixed in Nomad 1.7.4, 1.6.7, and 1.5.14.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-02-07 CVE Reserved
- 2024-02-08 CVE Published
- 2024-02-16 EPSS Updated
- 2024-09-26 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
- CWE-610: Externally Controlled Reference to a Resource in Another Sphere
CAPEC
- CAPEC-132: Symlink Attack
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hashicorp Search vendor "Hashicorp" | Nomad Search vendor "Hashicorp" for product "Nomad" | >= 1.5.13 < 1.5.14 Search vendor "Hashicorp" for product "Nomad" and version " >= 1.5.13 < 1.5.14" | - |
Affected
| ||||||
Hashicorp Search vendor "Hashicorp" | Nomad Search vendor "Hashicorp" for product "Nomad" | >= 1.6.6 < 1.6.7 Search vendor "Hashicorp" for product "Nomad" and version " >= 1.6.6 < 1.6.7" | - |
Affected
| ||||||
Hashicorp Search vendor "Hashicorp" | Nomad Search vendor "Hashicorp" for product "Nomad" | >= 1.7.3. < 1.7.4 Search vendor "Hashicorp" for product "Nomad" and version " >= 1.7.3. < 1.7.4" | - |
Affected
| ||||||
Hashicorp Search vendor "Hashicorp" | Nomad Search vendor "Hashicorp" for product "Nomad" | >= 1.5.13 < 1.5.14 Search vendor "Hashicorp" for product "Nomad" and version " >= 1.5.13 < 1.5.14" | enterprise |
Affected
| ||||||
Hashicorp Search vendor "Hashicorp" | Nomad Search vendor "Hashicorp" for product "Nomad" | >= 1.6.6 < 1.6.7 Search vendor "Hashicorp" for product "Nomad" and version " >= 1.6.6 < 1.6.7" | enterprise |
Affected
| ||||||
Hashicorp Search vendor "Hashicorp" | Nomad Search vendor "Hashicorp" for product "Nomad" | >= 1.7.3. < 1.7.4 Search vendor "Hashicorp" for product "Nomad" and version " >= 1.7.3. < 1.7.4" | enterprise |
Affected
|