CVE-2021-43415

HIGH

HashiCorp Nomad <1.0.13, 1.1.7, 1.2.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenticated users with job submission capabilities to bypass the configured allowed image paths. Fixed in 1.0.14, 1.1.8, and 1.2.1.

References (2)

Core 2
Core References
Product, Vendor Advisory x_refsource_misc
https://www.hashicorp.com/blog/category/nomad

Scores

CVSS v3 8.8
EPSS 0.0031
EPSS Percentile 53.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (3)
hashicorp/nomad 1.2.0 (2 CPE variants)
hashicorp/nomad 0 - 1.0.14Go
hashicorp/nomad 1.0.0 - 1.0.14 (2 CPE variants)
Published Dec 03, 2021
Tracked Since Feb 18, 2026