Job Parsing Vulnerability in HashiCorp Nomad and Nomad Enterprise
CVE-2022-24685
7.5HIGH
Summary
In HashiCorp Nomad and Nomad Enterprise, certain versions improperly validate HashiCorp Configuration Language (HCL) in the jobs parse endpoint, leading to potential scenarios of excessive CPU usage. This vulnerability is resolved in versions 1.0.18, 1.1.12, and 1.2.6, which enhance input validation mechanisms to prevent malformed job definitions from causing performance degradation.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved