{"id":"CVE-2022-24683","details":"HashiCorp Nomad and Nomad Enterprise 0.9.2 through 1.0.17, 1.1.11, and 1.2.5 allow operators with read-fs and alloc-exec (or job-submit) capabilities to read arbitrary files on the host filesystem as root.","aliases":["GHSA-wmrx-57hm-mw7r","GO-2022-0584"],"modified":"2026-08-12T03:51:19.841354457Z","published":"2022-02-17T16:36:37Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24683.json","unresolved_ranges":[{"extracted_events":[{"introduced":"0.9.2"},{"fixed":"1.0.17"}],"source":"DESCRIPTION"}],"cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://discuss.hashicorp.com"},{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2022-02-nomad-alloc-filesystem-and-container-escape/35560"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24683.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24683"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220318-0008/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hashicorp/nomad","events":[{"introduced":"ef1dc3ad82840da6ab3708a839229303f79ae293"},{"fixed":"7eb2ad21ae4a0a001cb89be92564fca09b1132e5"},{"introduced":"f99f1e27bb66bee36a1f3cdf00335e81e93ffff2"},{"fixed":"8469293aa07056a0f8682e76716e12f0178fe4c8"},{"introduced":"bee0c3e04eb4ce34b8ac22ff27fcb421a9dccec5"},{"fixed":"95514d569610f15ce49b4a7a1a6bfd3e7b3e7b4f"}],"database_specific":{"extracted_events":[{"introduced":"0.9.2"},{"fixed":"1.0.18"},{"introduced":"1.1.0"},{"fixed":"1.1.12"},{"introduced":"1.2.0"},{"fixed":"1.2.6"}],"source":"CPE_RANGE","cpe":["cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:*","cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:*"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-24683.json"}}],"schema_version":"1.9.0"}