HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NHashicorp Nomad
APPHashicorp0.9.0 – 0.10.50.11.0 – 0.11.40.12.0 – 0.12.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2023-1782CRITICAL9.9PL ✓same product
HashiCorp Nomad: obejście ACL przez nieuwierzytelnionych użytkowników
CVE-2022-30324CRITICAL9.8PL ✓same product
HashiCorp Nomad: privilege escalation przez podatności go-getter w artifact stanza
CVE-2020-7956CRITICAL9.8PL ✓same product
Nieprawidłowa walidacja certyfikatów TLS w HashiCorp Nomad — privilege escalation
CVE-2019-12618CRITICAL9.8PL ✓same product
Nieprawidłowa kontrola dostępu w HashiCorp Nomad przez sterownik exec
CVE-2025-4922HIGH8.1same product
Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule appli...