Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, identified as CVE-2024-10975, is fixed in Nomad Community Edition 1.9.2 and Nomad Enterprise 1.9.2, 1.8.7, and 1.7.15.
Metrics
Affected Vendors & Products
References
History
Thu, 07 Nov 2024 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 07 Nov 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, identified as CVE-2024-10975, is fixed in Nomad Community Edition 1.9.2 and Nomad Enterprise 1.9.2, 1.8.7, and 1.7.15. | |
Title | Nomad Vulnerable To Cross-Namespace Volume Creation Abusing CSI Write Permission | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: HashiCorp
Published: 2024-11-07T21:04:43.804Z
Updated: 2024-11-07T21:22:50.668Z
Reserved: 2024-11-07T19:05:40.525Z
Link: CVE-2024-10975
Vulnrichment
Updated: 2024-11-07T21:22:36.855Z
NVD
Status : Awaiting Analysis
Published: 2024-11-07T21:15:06.383
Modified: 2024-11-08T19:01:03.880
Link: CVE-2024-10975
Redhat
No data.