VYPR
Critical severity9.8NVD Advisory· Published Jun 2, 2022· Updated Jun 17, 2026

CVE-2022-30324

CVE-2022-30324

Description

HashiCorp Nomad and Nomad Enterprise version 0.2.0 up to 1.3.0 were impacted by go-getter vulnerabilities enabling privilege escalation through the artifact stanza in submitted jobs onto the client agent host. Fixed in 1.1.14, 1.2.8, and 1.3.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/hashicorp/nomadGo
>= 0.2.0, < 1.1.141.1.14
github.com/hashicorp/nomadGo
>= 1.2.0, < 1.2.81.2.8
github.com/hashicorp/nomadGo
>= 1.3.0, < 1.3.11.3.1

Affected products

6
  • Hashicorp/Nomad4 versions
    cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*+ 3 more
    • cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*range: >=0.2.0,<1.1.14
    • cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*range: >=0.2.0,<1.1.14
    • cpe:2.3:a:hashicorp:nomad:1.3.0:*:*:*:-:*:*:*
    • cpe:2.3:a:hashicorp:nomad:1.3.0:*:*:*:enterprise:*:*:*
  • ghsa-coords
    Range: >= 0.2.0, < 1.1.14

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.