Vulnerability in HashiCorp Nomad Affects Job Submission with Invalid URLs
CVE-2022-41606
6.5MEDIUM
What is CVE-2022-41606?
HashiCorp Nomad and Nomad Enterprise versions 1.0.2 through 1.2.12 and 1.3.5 are affected by a vulnerability that allows attackers to exploit invalid S3 or GCS URLs in artifact stanzas when job submissions are made. This flaw can lead to crashes of client agents, impacting the stability and reliability of the Nomad deployment. The vulnerability has been addressed in subsequent versions 1.2.13, 1.3.6, and 1.4.0, which users are encouraged to upgrade to in order to mitigate this issue.