We found results for “”
CVE-2021-32575
Good to know:
Date: June 17, 2021
HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged tasks on the same node. Fixed in 0.12.12, 1.0.5, and 1.1.0 RC1.
Language: Go
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Insufficient Information
NVD-CWE-noinfoInsufficient Isolation of System-Dependent Functions
CWE-1100Top Fix
Upgrade Version
Upgrade to version github.com/hashicorp/nomad - v1.0.5;github.com/hashicorp/nomad - v0.12.12
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | ADJACENT_NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | HIGH |
| Availability (A): | NONE |
CVSS v2
| Base Score: |
|
|---|---|
| Access Vector (AV): | ADJACENT |
| Access Complexity (AC): | LOW |
| Authentication (AU): | NONE |
| Confidentiality (C): | NONE |
| Integrity (I): | PARTIAL |
| Availability (A): | NONE |
| Additional information: |
Vulnerabilities
Projects
Contact Us


