High severity7.7NVD Advisory· Published Jul 23, 2024· Updated Jun 17, 2026
CVE-2024-6717
CVE-2024-6717
Description
HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/hashicorp/nomadGo | < 1.8.2 | 1.8.2 |
Affected products
11cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*+ 6 more
- cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*range: >=1.7.0,<1.7.10
- cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*range: >=1.7.0,<1.7.10
- cpe:2.3:a:hashicorp:nomad:1.6.12:*:*:*:-:*:*:*
- cpe:2.3:a:hashicorp:nomad:1.6.12:*:*:*:enterprise:*:*:*
- cpe:2.3:a:hashicorp:nomad:1.8.1:*:*:*:-:*:*:*
- cpe:2.3:a:hashicorp:nomad:1.8.1:*:*:*:enterprise:*:*:*
- (no CPE)range: 0
- ghsa-coords3 versionspkg:golang/github.com/hashicorp/nomadpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
< 1.8.2+ 2 more
- (no CPE)range: < 1.8.2
- (no CPE)range: < 0.0.20260114T191543-150000.1.137.1
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
- Range: 0
Patches
Vulnerability mechanics
References
5- discuss.hashicorp.com/t/hcsec-2024-15-nomad-vulnerable-to-allocation-directory-path-escape-through-archive-unpacking/68781nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-5mqx-rpxv-mvxjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-6717ghsaADVISORY
- github.com/hashicorp/nomad/commit/ef6cdec8847e0698d386d1fd3761743df758ef99ghsaWEB
- github.com/hashicorp/nomad/releases/tag/v1.8.2ghsaWEB
News mentions
0No linked articles in our index yet.