CVE-2023-0821
Published Feb 16, 2023
Last updated 2 years ago
Overview
- Description
- HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 jobs using a maliciously compressed artifact stanza source can cause excessive disk usage. Fixed in 1.2.16, 1.3.9, and 1.4.4.
- Source
- security@hashicorp.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity
- MEDIUM
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
- security@hashicorp.com
- CWE-409
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*", "vulnerable": true, "matchCriteriaId": "98DF3B6E-1C27-4843-BB28-1FA3AB012431", "versionEndExcluding": "1.2.15" }, { "criteria": "cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "F82F9A88-E6D7-4255-904B-2D7AA1C840D9", "versionEndExcluding": "1.2.15" }, { "criteria": "cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*", "vulnerable": true, "matchCriteriaId": "64FB8A46-BF26-460F-87E7-9FF51A9E3951", "versionEndExcluding": "1.3.9", "versionStartIncluding": "1.3.0" }, { "criteria": "cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "9120A20A-0F48-4402-A281-820CD0D9D295", "versionEndExcluding": "1.3.9", "versionStartIncluding": "1.3.0" }, { "criteria": "cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*", "vulnerable": true, "matchCriteriaId": "345CB160-3D34-4F84-8957-91BD1103D89F", "versionEndExcluding": "1.4.4", "versionStartIncluding": "1.4.0" }, { "criteria": "cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "9A6D8426-DD9C-4142-B55C-5C3263DAA62A", "versionEndExcluding": "1.4.4", "versionStartIncluding": "1.4.0" } ], "operator": "OR" } ] } ]