CVE-2024-6717

H

ashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:nomad:1.6.12:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:nomad:1.6.12:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:nomad:1.8.1:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:nomad:1.8.1:*:*:*:enterprise:*:*:*

History

02 Jan 2026, 20:23

Type Values Removed Values Added
First Time Hashicorp
Hashicorp nomad
CPE cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:nomad:1.8.1:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:nomad:1.6.12:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:nomad:1.6.12:*:*:*:-:*:*:*
cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:hashicorp:nomad:1.8.1:*:*:*:-:*:*:*
References () https://discuss.hashicorp.com/t/hcsec-2024-15-nomad-vulnerable-to-allocation-directory-path-escape-through-archive-unpacking/68781 - () https://discuss.hashicorp.com/t/hcsec-2024-15-nomad-vulnerable-to-allocation-directory-path-escape-through-archive-unpacking/68781 - Vendor Advisory

21 Nov 2024, 09:50

Type Values Removed Values Added
References () https://discuss.hashicorp.com/t/hcsec-2024-15-nomad-vulnerable-to-allocation-directory-path-escape-through-archive-unpacking/68781 - () https://discuss.hashicorp.com/t/hcsec-2024-15-nomad-vulnerable-to-allocation-directory-path-escape-through-archive-unpacking/68781 -

24 Jul 2024, 12:55

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-23 01:15

Updated : 2026-01-02 20:23


NVD link : CVE-2024-6717

Mitre link : CVE-2024-6717

CVE.ORG link : CVE-2024-6717


JSON object : View

Products Affected
CWE
CWE-610

Externally Controlled Reference to a Resource in Another Sphere