Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 888593 (CVE-2019-14802) - sys-cluster/nomad: environment leakage into template rendering
Summary: sys-cluster/nomad: environment leakage into template rendering
Status: RESOLVED INVALID
Alias: CVE-2019-14802
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://advisories.gitlab.com/advisor...
Whiteboard: B3 [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2022-12-27 03:01 UTC by John Helmert III
Modified: 2023-02-21 00:18 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-12-27 03:01:09 UTC
CVE-2019-14802:

HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applies to nomad/client/allocrunner/taskrunner/template.

Bit troubling that the "GMS" at URL was last modified on 2022-04-13,
but the CVE was only published today.

Please bump to 0.9.5.
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-02-21 00:18:16 UTC
Oh, I guess a vulnerable version was never in Gentoo.