Vulnerability Report: GO-2024-2538
- CVE-2024-1329, GHSA-c866-8gpw-p3mv
- Affects: github.com/hashicorp/nomad
- Published: Mar 04, 2024
- Modified: May 20, 2024
Symlink attack in github.com/hashicorp/nomad
For detailed information about this vulnerability, visit https://nvd.nist.gov/vuln/detail/CVE-2024-1329.
Affected Packages
-
PathGo VersionsSymbols
-
from v1.5.13 before v1.5.14, from v1.6.0 before v1.6.7, from v1.7.3 before v1.7.4
-
from v1.5.13 before v1.5.14, from v1.6.0 before v1.6.7, from v1.7.3 before v1.7.4
3 unexported affected symbols
- remotePrevAlloc.Migrate
- remotePrevAlloc.migrateAllocDir
- remotePrevAlloc.streamAllocDir
Aliases
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-1329
- https://github.com/hashicorp/nomad/issues/19888
- https://github.com/hashicorp/nomad/commit/b3209cbc6921e703b0e9984ce70c10b378665834
- https://github.com/hashicorp/nomad/commit/d1721c7a6fc1833778086603f818a822a34f445a
- https://github.com/hashicorp/nomad/commit/de55da677a21ac7572c0f4a8cd9abd5473c47a70
- https://discuss.hashicorp.com/t/hcsec-2024-03-nomad-vulnerable-to-arbitrary-write-through-symlink-attack
- https://vuln.go.dev/ID/GO-2024-2538.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.