Security Advisory

CVE-2024-1329

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-02-08 19:20:10
Last updated 2024-09-26 17:05:43
Assigner HashiCorp
State PUBLISHED

Description

HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. This vulnerability, CVE-2024-1329, is fixed in Nomad 1.7.4, 1.6.7, and 1.5.14.