Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-41606


HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.


Published

2022-10-12T00:15:10.537

Last Modified

2025-05-20T16:15:23.260

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hashicorp nomad < 1.2.13 Yes
Application hashicorp nomad < 1.2.13 Yes
Application hashicorp nomad < 1.3.6 Yes
Application hashicorp nomad < 1.3.6 Yes

References