Nomad Panics On Job Submission With Bad Artifact Stanza Source URL
Moderate severity
GitHub Reviewed
Published
Oct 12, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
< 1.2.13
>= 1.3.0, < 1.3.6
Patched versions
1.2.13
1.3.6
Description
Published by the National Vulnerability Database
Oct 12, 2022
Published to the GitHub Advisory Database
Oct 12, 2022
Reviewed
Oct 12, 2022
Last updated
Jan 27, 2023
HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.
References