HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destination. Fixed in 1.0.18, 1.1.12, and 1.2.6
Advisories
Source ID Title
EUVD EUVD EUVD-2022-1024 HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destination. Fixed in 1.0.18, 1.1.12, and 1.2.6
Github GHSA Github GHSA GHSA-gwmc-6795-qghj HashiCorp Nomad Artifact Download Race Condition
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T04:20:49.714Z

Reserved: 2022-02-09T00:00:00

Link: CVE-2022-24686

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-14T14:15:08.630

Modified: 2024-11-21T06:50:52.557

Link: CVE-2022-24686

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses