We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
In GitHub Security Advisory GHSA-c866-8gpw-p3mv, there is a vulnerability in the following Go packages or modules:
Cross references:
See doc/triage.md for instructions on how to triage this report.
modules: - module: github.com/hashicorp/nomad versions: - introduced: TODO (earliest fixed "1.7.4", vuln range "= 1.7.3") packages: - package: github.com/hashicorp/nomad - module: github.com/hashicorp/nomad versions: - introduced: TODO (earliest fixed "1.6.7", vuln range ">= 1.6.0, <= 1.6.6") packages: - package: github.com/hashicorp/nomad - module: github.com/hashicorp/nomad versions: - introduced: TODO (earliest fixed "1.5.14", vuln range "= 1.5.13") packages: - package: github.com/hashicorp/nomad summary: HashiCorp Nomad vulnerable to symlink attacks cves: - CVE-2024-1329 ghsas: - GHSA-c866-8gpw-p3mv references: - web: https://nvd.nist.gov/vuln/detail/CVE-2024-1329 - web: https://discuss.hashicorp.com/t/hcsec-2024-03-nomad-vulnerable-to-arbitrary-write-through-symlink-attack - report: https://github.com/hashicorp/nomad/issues/19888 - fix: https://github.com/hashicorp/nomad/commit/b3209cbc6921e703b0e9984ce70c10b378665834 - fix: https://github.com/hashicorp/nomad/commit/d1721c7a6fc1833778086603f818a822a34f445a - fix: https://github.com/hashicorp/nomad/commit/de55da677a21ac7572c0f4a8cd9abd5473c47a70 - advisory: https://github.com/advisories/GHSA-c866-8gpw-p3mv
The text was updated successfully, but these errors were encountered:
Change https://go.dev/cl/568056 mentions this issue: data/reports: add GO-2024-2538.yaml
data/reports: add GO-2024-2538.yaml
Sorry, something went wrong.
e1ab50e
tatianab
No branches or pull requests
In GitHub Security Advisory GHSA-c866-8gpw-p3mv, there is a vulnerability in the following Go packages or modules:
Cross references:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: