Description
HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47756 | HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2. |
Github GHSA |
GHSA-5mqx-rpxv-mvxj | HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration |
References
History
Fri, 02 Jan 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hashicorp
Hashicorp nomad |
|
| CPEs | cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:* cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:* cpe:2.3:a:hashicorp:nomad:1.6.12:*:*:*:-:*:*:* cpe:2.3:a:hashicorp:nomad:1.6.12:*:*:*:enterprise:*:*:* cpe:2.3:a:hashicorp:nomad:1.8.1:*:*:*:-:*:*:* cpe:2.3:a:hashicorp:nomad:1.8.1:*:*:*:enterprise:*:*:* |
|
| Vendors & Products |
Hashicorp
Hashicorp nomad |
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2024-08-01T21:41:04.313Z
Reserved: 2024-07-12T19:14:11.820Z
Link: CVE-2024-6717
Updated: 2024-08-01T21:41:04.313Z
Status : Analyzed
Published: 2024-07-23T01:15:09.190
Modified: 2026-01-02T20:23:38.783
Link: CVE-2024-6717
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA