HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged tasks on the same node. Fixed in 0.12.12, 1.0.5, and 1.1.0 RC1.
2021-06-17T19:15:07.933
2024-11-21T06:07:18.227
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:A/AC:L/Au:N/C:N/I:P/A:N
6.5
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hashicorp | nomad | ≤ 1.0.4 | Yes |
Application | hashicorp | nomad | ≤ 1.0.4 | Yes |