Nomad Spread Job Stanza May Trigger Panic in Servers
Moderate severity
GitHub Reviewed
Published
Feb 16, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Package
Affected versions
>= 0.9.0, < 1.0.18
>= 1.1.0, < 1.1.12
>= 1.2.0, < 1.2.6
Patched versions
1.0.18
1.1.12
1.2.6
Description
Published by the National Vulnerability Database
Feb 15, 2022
Published to the GitHub Advisory Database
Feb 16, 2022
Reviewed
Apr 4, 2022
Last updated
Feb 3, 2023
Nomad and Nomad Enterprise allows operators with job-submit capabilities to use the spread stanza in a way such that it can cause panic in Nomad servers. This vulnerability, CVE-2022-24684, was fixed in Nomad 1.0.18, 1.1.12, and 1.2.6.
References