HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.
| Software | From | Fixed in |
|---|---|---|
| hashicorp / nomad | - | 1.0.10 |
| hashicorp / nomad | - | 1.0.10.x |
| hashicorp / nomad | 1.1.1 | 1.1.4 |
github.com/hashicorp/nomad
|
- | 1.0.10 |
github.com/hashicorp/nomad
|
1.1.0 | 1.1.4 |