HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fixed in 1.0.18, 1.1.12, and 1.2.6.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1281 | HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fixed in 1.0.18, 1.1.12, and 1.2.6. |
Github GHSA |
GHSA-3382-r9q8-4hfg | HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T04:20:50.157Z
Reserved: 2022-02-09T00:00:00
Link: CVE-2022-24685
No data.
Status : Modified
Published: 2022-02-28T14:15:08.497
Modified: 2024-11-21T06:50:52.413
Link: CVE-2022-24685
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA