HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could cause arbitrary JavaScript to execute in the web UI. Fixed in 0.10.5.
| Software | From | Fixed in |
|---|---|---|
| hashicorp / nomad | 0.3 | 0.10.5 |