{"id":"CVE-2020-28348","details":"HashiCorp Nomad and Nomad Enterprise 0.9.0 up to 0.12.7 client Docker file sandbox feature may be subverted when not explicitly disabled or when using a volume mount type. Fixed in 0.12.8, 0.11.7, and 0.10.8.","aliases":["GHSA-5x92-p4p5-33c4","GO-2022-0770"],"modified":"2026-07-08T19:03:15.978213Z","published":"2020-11-24T03:15:13.183Z","references":[{"type":"ADVISORY","url":"https://github.com/hashicorp/nomad/blob/master/CHANGELOG.md#0128-november-10-2020"},{"type":"REPORT","url":"https://github.com/hashicorp/nomad/issues/9303"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hashicorp/nomad","events":[{"introduced":"d77075ff2053cd2e23b6a0f8b09cd43424bed792"},{"fixed":"75dcbeee75958ca10503e3f8245cdd665eb5624c"},{"introduced":"ca5cd15eeffd40b68043c94eefff1ec7e6dc703f"},{"fixed":"69d49c17ae51ec6f11df243b068d7739168591e3"},{"introduced":"b1aa9e2166e72b75d7e0ed39ff456393beb0f421"},{"fixed":"99fa2774301199ee20e661c7c1832a6ee1d5c553"}],"database_specific":{"cpe":["cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*","cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*"],"extracted_events":[{"introduced":"0.9.0"},{"fixed":"0.10.8"},{"introduced":"0.11.0"},{"fixed":"0.11.7"},{"introduced":"0.12.0"},{"fixed":"0.12.8"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-28348.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}