CVE-2022-24685 – github.com/hashicorp/nomad
Package
Manager: go
Name: github.com/hashicorp/nomad
Vulnerable Version: >=1.0.0 <1.0.17 || >=1.1.0 <1.1.12 || >=1.2.0 <1.2.6
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00693 pctl0.70971
Details
HashiCorp Nomad vulnerable to Allocation of Resources Without Limits or Throttling HashiCorp Nomad and Nomad Enterprise 1.x before 1.0.17, 1.1.x before 1.1.12, and 1.2.x before 1.2.6 is vulnerable to Allocation of Resources Without Limits or Throttling.
Metadata
Created: 2022-03-01T00:00:28Z
Modified: 2022-08-12T12:53:18Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-3382-r9q8-4hfg/GHSA-3382-r9q8-4hfg.json
CWE IDs: ["CWE-770"]
Alternative ID: GHSA-3382-r9q8-4hfg
Finding: F067
Auto approve: 1