HashiCorp nomad是美国HashiCorp公司开源的一个集群管理与调度工具。 HashiCorp Nomad存在授权问题漏洞,该漏洞源于未对Docker任务驱动的主机命名空间模式选项强制执行allow_privileged限制,可能导致经过身份验证的作业提交者在主机命名空间中运行容器并访问属于主机或同一客户端上其他工作负载的信息。以下版本受到影响:Nomad 2.0.4之前版本、Nomad Enterprise 2.0.4之前版本、1.11.8之前版本和1.10.14之前版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HashiCorp | Nomad | 0.4.1< 2.0.4 |
affected |
| HashiCorp | Nomad Enterprise | 0.4.1< 2.0.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashiCorp | Nomad | 0.4.1 ~ 2.0.4 | - |
|
| HashiCorp | Nomad Enterprise | 0.4.1 ~ 2.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14891 | 8.7 HIGH | Nomad vulnerable to sandbox escape in Docker task driver |
| CVE-2026-14362 | 4.9 MEDIUM | Denial of service via crafted push/pull gossip message in memberlist |
| CVE-2026-14361 | 4.7 MEDIUM | Consul-template is vulnerable to path redirection in writeToFile through symlink attack |
| CVE-2026-14896 | 4.2 MEDIUM | Nomad vulnerable to cross-namespace host volume claim deletion |
No comments yet