Description
HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. This vulnerability, CVE-2024-1329, is fixed in Nomad 1.7.4, 1.6.7, and 1.5.14.
Scores
CVSS v3
7.7
EPSS
0.0033
EPSS Percentile
56.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-610
CWE-59
Status
published
Products (2)
hashicorp/nomad
1.5.13 - 1.5.14 (2 CPE variants)
hashicorp/nomad
1.5.13 - 1.5.14Go
Published
Feb 08, 2024
Tracked Since
Feb 18, 2026