CVE-2024-10975
CVSS 3.1 Score 7.7 of 10 (high)
Details
Published Nov 7, 2024
Updated: Nov 8, 2024
CWE ID 863
Summary
CVE-2024-10975 is a vulnerability affecting Nomad's volume specification. Unauthorized Container Storage Interface (CSI) volume writes can be exploited to create arbitrary volumes in other namespaces, posing a significant security risk. This issue, identified as CVE-2024-10975, has been resolved in Nomad Community Edition 1.9.2 and Enterprise versions 1.9.2, 1.8.7, and 1.7.15. Users are advised to update their Nomad installations to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- HashiCorp Nomad
Affected Vendors
- HashiCorp Inc.