Missing Authorization in Nomad Enterprise and Nomad - CVE-2024-10975
Published: November 8, 2024
Vulnerability details
The vulnerability allows a remote user to perform unauthorized Container Storage Interface (CSI) volume writes.
The vulnerability exists due to missing authorization checks when creating or registering external storage volumes. A remote user with csi-write-volume capability in a namespace can perform cross-namespace volume creation using the Nomad volume create or volume register commands.
Affected software
Nomad
How to mitigate CVE-2024-10975
Nomad - update to 1.9.2