Permissions, Privileges, and Access Controls in Nomad Enterprise and Nomad - CVE-2021-37218

 

Permissions, Privileges, and Access Controls in Nomad Enterprise and Nomad - CVE-2021-37218

Published: August 27, 2021


Vulnerability identifier: #VU56139
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-37218
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions. A remote authenticated attacker can directly communicate with the server agent’s Raft RPC layer which leads to security restrictions bypass and privilege escalation.


Affected software

Nomad Enterprise
Nomad

How to mitigate CVE-2021-37218

Install updates from vendor's website.

Nomad Enterprise - addressed in versions 1.0.10, 1.1.4
Nomad - addressed in versions 1.0.10, 1.1.4

External References

Related Security Bulletins