Alpine: nomad: security update to 1.2.6-r0

high Tenable Cloud Security Plugin ID 405865

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs
and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.
(CVE-2022-24683)

- HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate
signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10
and 1.1.4. (CVE-2021-37218)

- HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled,
allowed authenticated users with job submission capabilities to bypass the configured allowed image paths.
Fixed in 1.0.14, 1.1.8, and 1.2.1. (CVE-2021-43415)

- net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the
header canonicalization cache via HTTP/2 requests. (CVE-2021-44716)

- Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or
unintended network connection as a consequence of erroneous closing of file descriptor 0 after file-
descriptor exhaustion. (CVE-2021-44717)

See Also

https://security.alpinelinux.org/vuln/CVE-2021-37218

https://security.alpinelinux.org/vuln/CVE-2021-43415

https://security.alpinelinux.org/vuln/CVE-2021-44716

https://security.alpinelinux.org/vuln/CVE-2021-44717

https://security.alpinelinux.org/vuln/CVE-2022-24683

https://security.alpinelinux.org/vuln/CVE-2022-24684

https://security.alpinelinux.org/vuln/CVE-2022-24685

https://security.alpinelinux.org/vuln/CVE-2022-24686

Plugin Details

Severity: High

ID: 405865

Version: Revision 1.27

Type: Local

Published: 10/31/2023

Updated: 3/13/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2022-24683

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2021-43415

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/7/2021

Reference Information

CVE: CVE-2021-37218, CVE-2021-43415, CVE-2021-44716, CVE-2021-44717, CVE-2022-24683, CVE-2022-24684, CVE-2022-24685, CVE-2022-24686