Lack of data validation - Path Traversal In github.com/hashicorp/nomad
Description
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.8.2 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.