CVE-2024-1329

HIGH

HashiCorp Nomad 1.5.13-1.6.6 and 1.7.3 - Arbitrary File Write via Symlink Attack

Title source: llm
STIX 2.1

Description

HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. This vulnerability, CVE-2024-1329, is fixed in Nomad 1.7.4, 1.6.7, and 1.5.14.

Scores

CVSS v3 7.7
EPSS 0.0062
EPSS Percentile 44.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-610 CWE-59
Status published
Products (2)
hashicorp/nomad 1.5.13 - 1.5.14 (2 CPE variants)
hashicorp/nomad 1.5.13 - 1.5.14Go
Published Feb 08, 2024
Tracked Since Feb 18, 2026