HashiCorp nomad是美国HashiCorp公司开源的一个集群管理与调度工具。 HashiCorp Nomad存在授权问题漏洞,该漏洞源于动态主机卷功能中存在跨命名空间授权绕过,可能导致持有某个命名空间中主机卷删除权限的操作员删除属于另一个命名空间中作业的粘性卷声明。以下版本受到影响:Nomad 0.4.1至2.0.4之前版本、Nomad Enterprise 1.10.14之前版本、1.10.14至1.11.8之前版本和0.4.1至2.0.4之前版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HashiCorp | Nomad | 0.4.1< 2.0.4 |
affected |
| HashiCorp | Nomad Enterprise | 0.4.1< 2.0.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashiCorp | Nomad | 0.4.1 ~ 2.0.4 | - |
|
| HashiCorp | Nomad Enterprise | 0.4.1 ~ 2.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14891 | 8.7 HIGH | Nomad vulnerable to sandbox escape in Docker task driver |
| CVE-2026-14373 | 7.7 HIGH | Nomad Docker driver Linux host namespace bypass |
| CVE-2026-14362 | 4.9 MEDIUM | Denial of service via crafted push/pull gossip message in memberlist |
| CVE-2026-14361 | 4.7 MEDIUM | Consul-template is vulnerable to path redirection in writeToFile through symlink attack |
No comments yet