CVE-2021-37218

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
07/09/2021
Last modified:
13/09/2021

Description

HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:* 1.0.10 (excluding)
cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:* 1.0.10 (including)
cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:* 1.1.1 (including) 1.1.4 (excluding)
cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:* 1.1.1 (including) 1.1.4 (excluding)