logo

CVE-2022-24685 github.com/hashicorp/nomad

Package

Manager: go
Name: github.com/hashicorp/nomad
Vulnerable Version: >=1.0.0 <1.0.17 || >=1.1.0 <1.1.12 || >=1.2.0 <1.2.6

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00693 pctl0.70971

Details

HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling HashiCorp Nomad and Nomad Enterprise 1.x before 1.0.17, 1.1.x before 1.1.12, and 1.2.x before 1.2.6 is vulnerable to Allocation of Resources Without Limits or Throttling.

Metadata

Created: 2022-03-01T00:00:28Z
Modified: 2022-08-12T12:53:18Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-3382-r9q8-4hfg/GHSA-3382-r9q8-4hfg.json
CWE IDs: ["CWE-770"]
Alternative ID: GHSA-3382-r9q8-4hfg
Finding: F067
Auto approve: 1