Show filters
48 Total Results
Displaying 41-48 of 48
Sort by:
Attacker Value
Unknown

CVE-2020-4092

Disclosure Date: May 06, 2020 (last updated February 21, 2025)
"If port encryption is not enabled on the Domino Server, HCL Nomad on Android and iOS Platforms will communicate in clear text and does not currently have a user interface option to change the setting to request an encrypted communication channel with the Domino server. This can potentially expose sensitive information including but not limited to server names, user IDs and document content."
Attacker Value
Unknown

CVE-2020-10944

Disclosure Date: April 28, 2020 (last updated February 21, 2025)
HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could cause arbitrary JavaScript to execute in the web UI. Fixed in 0.10.5.
Attacker Value
Unknown

CVE-2020-10257

Disclosure Date: March 10, 2020 (last updated February 21, 2025)
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Attacker Value
Unknown

CVE-2020-7218

Disclosure Date: January 31, 2020 (last updated February 21, 2025)
HashiCorp Nomad and Nonad Enterprise up to 0.10.2 HTTP/RPC services allowed unbounded resource usage, and were susceptible to unauthenticated denial of service. Fixed in 0.10.3.
Attacker Value
Unknown

CVE-2020-7956

Disclosure Date: January 31, 2020 (last updated February 21, 2025)
HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.
Attacker Value
Unknown

CVE-2019-12618

Disclosure Date: August 12, 2019 (last updated November 27, 2024)
HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.
0
Attacker Value
Unknown

CVE-2019-1003092

Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A cross-site request forgery vulnerability in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
0
Attacker Value
Unknown

CVE-2019-1003093

Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.