HashiCorp Nomad是美国HashiCorp公司的一个简单灵活的调度器和编排器。用于在本地和云中大规模管理容器和非容器化应用程序。 HashiCorp Nomad 0.1.2之前版本存在后置链接漏洞,该漏洞源于符号链接攻击,可能导致在客户端主机上以Nomad进程用户身份进行任意文件读写。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HashiCorp | Shared library | 0.1.0< 0.1.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HashiCorp | Shared library | 0.1.0 ~ 0.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-7474 | 8.8 HIGH | Nomad vulnerable to path traversal in dynamic host volume which may lead to code execution |
| CVE-2026-6959 | 6.0 MEDIUM | Nomad vulnerable to arbitrary file read/write on client host through symlink attack |
| CVE-2026-5061 | 4.7 MEDIUM | Consul-template vulnerable to sandbox path bypass in file helper via a symlink attack |
No comments yet