VYPR

Nomad Enterprise

by Hashicorp

Source repositories

CVEs (29)

  • CVE-2023-3300MedJul 20, 2023
    risk 0.27cvss 5.3epss 0.01

    HashiCorp Nomad and Nomad Enterprise 0.11.0 up to 1.5.6 and 1.4.1 HTTP search API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. Fixed in 1.6.0, 1.5.7, and 1.4.1.

  • CVE-2023-3072MedJul 20, 2023
    risk 0.27cvss 4.1epss 0.00

    HashiCorp Nomad and Nomad Enterprise 0.7.0 up to 1.5.6 and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.

  • CVE-2022-3866MedNov 10, 2022
    risk 0.26cvss 5.0epss 0.01

    HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.

  • CVE-2023-3299LowJul 20, 2023
    risk 0.22cvss 3.4epss 0.01

    HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.

  • CVE-2023-1296LowMar 14, 2023
    risk 0.18cvss 2.7epss 0.01

    HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.5.0 did not correctly enforce deny policies applied to a workload’s variables. Fixed in 1.4.6 and 1.5.1.

  • CVE-2022-3867LowNov 10, 2022
    risk 0.11cvss 2.7epss 0.00

    HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.

  • CVE-2026-14896MedJul 8, 2026
    risk 0.00cvss 4.2epss 0.00

    HashiCorp Nomad and Nomad Enterprise are vulnerable to a cross-namespace authorization bypass in the dynamic host volumes feature that may allow an operator holding the host volume delete permission in one namespace to delete a sticky volume claim belonging to a job in another…

  • CVE-2026-14891HigJul 8, 2026
    risk 0.00cvss 8.7epss 0.00

    HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host.…

  • CVE-2020-27195CriOct 22, 2020
    risk 0.00cvss 9.1epss 0.01

    HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6

Page 2 of 2