#VU56139 Permissions, Privileges, and Access Controls in Nomad and Nomad Enterprise - CVE-2021-37218
Published: August 27, 2021
Nomad
Nomad Enterprise
HashiCorp
Description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions. A remote authenticated attacker can directly communicate with the server agent’s Raft RPC layer which leads to security restrictions bypass and privilege escalation.