Arbitrary Cross-Namespace Volume Creation Vulnerability
CVE-2024-10975
7.7HIGH
What is CVE-2024-10975?
The Nomad volume specification is susceptible to a vulnerability that permits arbitrary cross-namespace volume creation. This occurs due to unauthorized writes via the Container Storage Interface (CSI), which does not adequately enforce proper permissions. Attackers can exploit this vulnerability to interfere with or manipulate volumes across different namespaces, potentially leading to data leaks or unauthorized access to sensitive information. The issue has been addressed in the releases of Nomad Community Edition 1.9.2 and Nomad Enterprise versions 1.9.2, 1.8.7, and 1.7.15.
Affected Version(s)
Nomad 64 bit 1.3.0 < 1.9.2
Nomad Enterprise 64 bit 1.3.0 < 1.9.2