HashiCorp Nomad Artifact Download Race Condition
Moderate severity
GitHub Reviewed
Published
Feb 15, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Package
Affected versions
>= 0.3.0, < 1.0.18
>= 1.1.0, < 1.1.12
>= 1.2.0, < 1.2.6
Patched versions
1.0.18
1.1.12
1.2.6
Description
Published by the National Vulnerability Database
Feb 14, 2022
Published to the GitHub Advisory Database
Feb 15, 2022
Reviewed
Mar 18, 2022
Last updated
Feb 3, 2023
HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destination. This issue is fixed in 1.0.18, 1.1.12, and 1.2.6.
References