HashiCorp Nomad and Nomad Enterprise up to version 1.0.4 bridge networking mode allows ARP spoofing from other bridged tasks on the same node. Fixed in 0.12.12, 1.0.5, and 1.1.0 RC1.
https://www.hashicorp.com/blog/category/nomad
https://discuss.hashicorp.com/t/hcsec-2021-14-nomad-bridge-networking-mode-allows-arp-spoofing-from-other-bridged-tasks-on-same-node/24296
Source: Mitre, NVD
Published: 2021-06-17
Updated: 2021-06-22
Base Score: 3.3
Vector: CVSS2#AV:A/AC:L/Au:N/C:N/I:P/A:N
Severity: Low
Base Score: 6.5
Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity: Medium
EPSS: 0.00182