—
GO-2024-2538
Symlink attack in github.com/hashicorp/nomad
Quick fix
GO-2024-2538 — github.com/hashicorp/nomad: upgrade to the fixed version with the command below.
go get github.com/hashicorp/nomad@v1.5.14Details
Symlink attack in github.com/hashicorp/nomad
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/nomad
Introduced in:
1.5.13Fixed in: 1.5.14Fix
go get github.com/hashicorp/nomad@v1.5.14References
- https://nvd.nist.gov/vuln/detail/CVE-2024-1329[ADVISORY]
- https://github.com/hashicorp/nomad/issues/19888[REPORT]
- https://github.com/hashicorp/nomad/commit/b3209cbc6921e703b0e9984ce70c10b378665834[FIX]
- https://github.com/hashicorp/nomad/commit/d1721c7a6fc1833778086603f818a822a34f445a[FIX]
- https://github.com/hashicorp/nomad/commit/de55da677a21ac7572c0f4a8cd9abd5473c47a70[FIX]
- https://discuss.hashicorp.com/t/hcsec-2024-03-nomad-vulnerable-to-arbitrary-write-through-symlink-attack[WEB]