n HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability.
Configuration 1 (hide)
|
29 Dec 2025, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://discuss.hashicorp.com/t/hcsec-2024-17-nomad-vulnerable-to-allocation-directory-escape-on-non-existing-file-paths-through-archive-unpacking/69293 - Vendor Advisory | |
| CPE | cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:* cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:* |
|
| First Time |
Hashicorp
Hashicorp nomad |
25 Sep 2024, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability. |
15 Aug 2024, 13:01
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2024-08-15 00:15
Updated : 2025-12-29 17:16
NVD link : CVE-2024-7625
Mitre link : CVE-2024-7625
CVE.ORG link : CVE-2024-7625
JSON object : View
Externally Controlled Reference to a Resource in Another Sphere