CVE-2024-12678
20.12.2024, 02:15
Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace through unredacted workload identity tokens. This vulnerability, identified as CVE-2024-12678, is fixed in Nomad Community Edition 1.9.4 and Nomad Enterprise 1.9.4, 1.8.8, and 1.7.16.Enginsight| Vendor | Product | Version |
|---|---|---|
| hashicorp | nomad | 1.4.0 ≤ 𝑥 < 1.7.16 |
| hashicorp | nomad | 1.4.0 ≤ 𝑥 < 1.9.4 |
| hashicorp | nomad | 1.8.0 ≤ 𝑥 < 1.8.8 |
| hashicorp | nomad | 1.9.0 ≤ 𝑥 < 1.9.4 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration