Risk Scores
CVSS v3.1
7.699999809265137
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
EPSS Score
0.29%
52.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | hashicorp/nomad | 0 |
| HashiCorp | Nomad | 0 |
| hashicorp | nomad | 1.7.0, 1.6.12, 1.8.1 |
| HashiCorp | Nomad Enterprise | 0 |
Timeline
- Jul 23, 2024 CVE Published
- Jul 23, 2024 EPSS Score
- Aug 13, 2024 EPSS Score
- Sep 3, 2024 EPSS Score
- Sep 24, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Oct 15, 2024 EPSS Score
- Nov 5, 2024 EPSS Score
- Nov 8, 2024 Coalition ESS Score
- Nov 26, 2024 EPSS Score
- Dec 18, 2024 EPSS Score
- Jan 8, 2025 EPSS Score
References
- https://discuss.hashicorp.com/t/hcsec-2024-15-nomad-vulnerable-to-allocation-directory-path-escape-through-archive-unpacking/68781 url
- https://nvd.nist.gov/vuln/detail/CVE-2024-6717 advisory
- https://github.com/hashicorp/nomad/commit/ef6cdec8847e0698d386d1fd3761743df758ef99 url
- https://github.com/hashicorp/nomad package
- https://github.com/hashicorp/nomad/releases/tag/v1.8.2 url