CVE-2024-1329
HIGHHashiCorp Nomad 1.5.13-1.6.6 and 1.7.3 - Arbitrary File Write via Symlink Attack
Title source: llmDescription
HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. This vulnerability, CVE-2024-1329, is fixed in Nomad 1.7.4, 1.6.7, and 1.5.14.
References (1)
Core 1
Core References
Scores
CVSS v3
7.7
EPSS
0.0062
EPSS Percentile
44.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-610
CWE-59
Status
published
Products (2)
hashicorp/nomad
1.5.13 - 1.5.14 (2 CPE variants)
hashicorp/nomad
1.5.13 - 1.5.14Go
Published
Feb 08, 2024
Tracked Since
Feb 18, 2026