CVE-2024-7625

CVSS 3.1 Score 5.8 of 10 (medium)

Details

Published Aug 15, 2024
CWE ID 610

Summary

CVE-2024-7625 is a vulnerability affecting HashiCorp Nomad and Nomad Enterprise versions 0.6.1 to 1.16.13, 1.7.10, and 1.8.2. The issue lies in the archive unpacking process, which allows writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability could be exploited by an attacker who has already gained access to the Nomad client agent at the source allocation. By leveraging this vulnerability, the attacker could potentially cause unintended changes or damage to the system. The vulnerability has been addressed in Nomad 1.6.14, 1.7.11, and 1.8.3.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • HashiCorp Nomad

Affected Vendors

  • HashiCorp Inc.