CVE-2024-10975
07.11.2024, 21:15
Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, identified as CVE-2024-10975, is fixed in Nomad Community Edition 1.9.2 and Nomad Enterprise 1.9.2, 1.8.7, and 1.7.15.Enginsight| Vendor | Product | Version |
|---|---|---|
| hashicorp | nomad | 1.3.0 ≤ 𝑥 < 1.7.15 |
| hashicorp | nomad | 1.3.0 ≤ 𝑥 < 1.9.2 |
| hashicorp | nomad | 1.8.0 ≤ 𝑥 < 1.8.7 |
| hashicorp | nomad | 1.9.0 ≤ 𝑥 < 1.9.2 |
𝑥
= Vulnerable software versions
Ubuntu Releases