Show filters
48 Total Results
Displaying 21-30 of 48
Sort by:
Attacker Value
Unknown
CVE-2022-34909
Disclosure Date: February 27, 2023 (last updated October 08, 2023)
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It allows SQL Injection, by which an attacker can bypass authentication and retrieve data that is stored in the database.
0
Attacker Value
Unknown
CVE-2022-34908
Disclosure Date: February 27, 2023 (last updated October 08, 2023)
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features do not require any token or cookie in a request. Therefore, an attacker may send a simple HTTP request to the right endpoint, and obtain authorization to retrieve application data.
0
Attacker Value
Unknown
CVE-2023-0821
Disclosure Date: February 16, 2023 (last updated October 08, 2023)
HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4.
0
Attacker Value
Unknown
CVE-2019-14802
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applies to nomad/client/allocrunner/taskrunner/template.
0
Attacker Value
Unknown
CVE-2022-3867
Disclosure Date: November 10, 2022 (last updated December 22, 2024)
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
0
Attacker Value
Unknown
CVE-2022-3866
Disclosure Date: November 10, 2022 (last updated December 22, 2024)
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.
0
Attacker Value
Unknown
CVE-2022-41606
Disclosure Date: October 12, 2022 (last updated October 08, 2023)
HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.
0
Attacker Value
Unknown
CVE-2022-30324
Disclosure Date: June 02, 2022 (last updated October 07, 2023)
HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.
0
Attacker Value
Unknown
CVE-2022-24685
Disclosure Date: February 28, 2022 (last updated February 23, 2025)
HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fixed in 1.0.18, 1.1.12, and 1.2.6.
0
Attacker Value
Unknown
CVE-2022-24683
Disclosure Date: February 17, 2022 (last updated October 07, 2023)
HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.
0