CVE-2024-6717

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/07/2024
Last modified:
02/01/2026

Description

HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:* 1.7.0 (including) 1.7.10 (excluding)
cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:* 1.7.0 (including) 1.7.10 (excluding)
cpe:2.3:a:hashicorp:nomad:1.6.12:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:nomad:1.6.12:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:nomad:1.8.1:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:nomad:1.8.1:*:*:*:enterprise:*:*:*