CVE-2024-6717 PUBLISHED CVSS 7.699999809265137 HIGH

HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.

EPSS 0.29% · 52.2th percentile

Risk Scores

CVSS v3.1
7.699999809265137
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
EPSS Score
0.29%
52.2th percentile

Affected Products

VendorProductVersions
github.comhashicorp/nomad0
HashiCorpNomad0
hashicorpnomad1.7.0, 1.6.12, 1.8.1
HashiCorpNomad Enterprise0

Timeline

References

Open in Interactive Console →