HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2024-08-01T21:41:04.313Z
Reserved: 2024-07-12T19:14:11.820Z
Link: CVE-2024-6717

Updated: 2024-08-01T21:41:04.313Z

Status : Awaiting Analysis
Published: 2024-07-23T01:15:09.190
Modified: 2024-11-21T09:50:10.447
Link: CVE-2024-6717

No data.