Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 846629 (CVE-2022-30324) - <sys-cluster/nomad-1.2.13: vulnerability in bundled go-getter leads to client privilege escalation
Summary: <sys-cluster/nomad-1.2.13: vulnerability in bundled go-getter leads to client...
Status: RESOLVED FIXED
Alias: CVE-2022-30324
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://github.com/hashicorp/nomad/is...
Whiteboard: ~3 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2022-05-21 01:01 UTC by John Helmert III
Modified: 2022-10-26 22:05 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-05-21 01:01:16 UTC
"A vulnerability was identified in the go-getter library that Nomad and Nomad Enterprise (“Nomad”) uses for its artifacts such that a specially crafted Nomad jobspec can be used for privilege escalation onto client agent hosts. This vulnerability affects Nomad versions 0.2.0 through 1.3.0, and is fixed in the 1.1.14, 1.2.8, and 1.3.1 releases."

Please bump to 1.2.8.
Comment 1 William Hubbs gentoo-dev 2022-10-26 19:30:15 UTC
This has been fixed in the tree.

Thanks,

William