Permissions, Privileges, and Access Controls in Nomad Enterprise and Nomad - CVE-2021-37218
Published: August 27, 2021
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions. A remote authenticated attacker can directly communicate with the server agent’s Raft RPC layer which leads to security restrictions bypass and privilege escalation.
Affected software
Nomad
How to mitigate CVE-2021-37218
Nomad - addressed in versions 1.0.10, 1.1.4