CVE-2024-1329

HIGH

Hashicorp Nomad < 1.5.14 - Symlink Following

Title source: rule
STIX 2.1

Description

HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. This vulnerability, CVE-2024-1329, is fixed in Nomad 1.7.4, 1.6.7, and 1.5.14.

Scores

CVSS v3 7.7
EPSS 0.0033
EPSS Percentile 56.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-610 CWE-59
Status published
Products (2)
hashicorp/nomad 1.5.13 - 1.5.14 (2 CPE variants)
hashicorp/nomad 1.5.13 - 1.5.14Go
Published Feb 08, 2024
Tracked Since Feb 18, 2026