#VU100098 Missing Authorization in Nomad and Nomad Enterprise - CVE-2024-10975
Published: November 8, 2024
Nomad
Nomad Enterprise
HashiCorp
Description
The vulnerability allows a remote user to perform unauthorized Container Storage Interface (CSI) volume writes.
The vulnerability exists due to missing authorization checks when creating or registering external storage volumes. A remote user with csi-write-volume capability in a namespace can perform cross-namespace volume creation using the Nomad volume create or volume register commands.