Show filters
48 Total Results
Displaying 21-30 of 48
Sort by:
Attacker Value
Unknown

CVE-2022-34909

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It allows SQL Injection, by which an attacker can bypass authentication and retrieve data that is stored in the database.
Attacker Value
Unknown

CVE-2022-34908

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechanism; however, some features do not require any token or cookie in a request. Therefore, an attacker may send a simple HTTP request to the right endpoint, and obtain authorization to retrieve application data.
Attacker Value
Unknown

CVE-2023-0821

Disclosure Date: February 16, 2023 (last updated October 08, 2023)
HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4.
Attacker Value
Unknown

CVE-2019-14802

Disclosure Date: December 26, 2022 (last updated October 08, 2023)
HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applies to nomad/client/allocrunner/taskrunner/template.
Attacker Value
Unknown

CVE-2022-3867

Disclosure Date: November 10, 2022 (last updated December 22, 2024)
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
Attacker Value
Unknown

CVE-2022-3866

Disclosure Date: November 10, 2022 (last updated December 22, 2024)
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.
Attacker Value
Unknown

CVE-2022-41606

Disclosure Date: October 12, 2022 (last updated October 08, 2023)
HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.
Attacker Value
Unknown

CVE-2022-30324

Disclosure Date: June 02, 2022 (last updated October 07, 2023)
HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.
Attacker Value
Unknown

CVE-2022-24685

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
HashiCorp Nomad and Nomad Enterprise 1.0.17, 1.1.11, and 1.2.5 allow invalid HCL for the jobs parse endpoint, which may cause excessive CPU usage. Fixed in 1.0.18, 1.1.12, and 1.2.6.
Attacker Value
Unknown

CVE-2022-24683

Disclosure Date: February 17, 2022 (last updated October 07, 2023)
HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.