Description

In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability.

INFO

Published Date :

2024-08-14T23:20:17.888Z

Last Modified :

2025-01-09T19:19:01.219Z

Source :

HashiCorp
AFFECTED PRODUCTS

The following products are affected by CVE-2024-7625 vulnerability.

Vendors Products
Hashicorp
  • Nomad
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-7625.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact