CVE-2024-10975

CVSS 3.1 Score 7.7 of 10 (high)

Details

Published Nov 7, 2024
Updated: Nov 8, 2024
CWE ID 863

Summary

CVE-2024-10975 is a vulnerability affecting Nomad's volume specification. Unauthorized Container Storage Interface (CSI) volume writes can be exploited to create arbitrary volumes in other namespaces, posing a significant security risk. This issue, identified as CVE-2024-10975, has been resolved in Nomad Community Edition 1.9.2 and Enterprise versions 1.9.2, 1.8.7, and 1.7.15. Users are advised to update their Nomad installations to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • HashiCorp Nomad

Affected Vendors

  • HashiCorp Inc.