CVE-2024-6717 Vulnerability Details

  /     /     /  

CVE-2024-6717 Metadata Quick Info

CVE Published: 23/07/2024 | CVE Updated: 01/08/2024 | CVE Year: 2024
Source: HashiCorp | Vendor: HashiCorp | Product: Nomad
Status : PUBLISHED

CVE-2024-6717 Description

HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.

Metrics

CVSS Version: 3.1 | Base Score: 7.7 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-610
CWE Name: CWE-610: Externally Controlled Reference to a Resource in Another Sphere
Source: HashiCorp

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-126
CAPEC Description: CAPEC-126: Path Traversal


Source: NVD (National Vulnerability Database).