Nomad Archives Vulnerability: Write Access Outside Allocation Directory
CVE-2024-7625
What is CVE-2024-7625?
In HashiCorp Nomad and Nomad Enterprise versions from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, an issue exists within the archive unpacking process that permits unauthorized writes to locations outside of allocated directories during the migration of those directories. This occurs when multiple archive headers point to the same target file, potentially leading to significant security risks. Access to the Nomad client agent at the source allocation is required to exploit this vulnerability, which emphasizes the need for secure handling of client agent access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Nomad 64 bit 0.6.1 < 1.8.3
Nomad Enterprise 64 bit 0.6.1 < 1.8.3
References
CVSS V3.1
Timeline
Vulnerability published