HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/hashicorp/nomad(Go) | 0.2.0 | 1.1.14 | N/A |
| github.com/hashicorp/nomad(Go) | 1.2.0 | 1.2.8 | N/A |
| github.com/hashicorp/nomad(Go) | 1.3.0 | 1.3.1 | N/A |
CVSS Metrics