Bug 2156437 (CVE-2019-14802) - CVE-2019-14802 hashicorp/nomad: Information Exposure Through Environmental Variables
Summary: CVE-2019-14802 hashicorp/nomad: Information Exposure Through Environmental Va...
Keywords:
Status: NEW
Alias: CVE-2019-14802
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2158333 2158334 2158335 2158336 2158337 2158338
Blocks: 2156439
TreeView+ depends on / blocked
 
Reported: 2022-12-27 03:43 UTC by Avinash Hanwate
Modified: 2023-08-03 08:30 UTC (History)
9 users (show)

Fixed In Version: nomad 0.9.5
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in HashiCorp Nomad. In affected versions of Nomad, when rendering a task template, all environment variables were available to the rendering task. As a fix, only task environment variables are used.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Avinash Hanwate 2022-12-27 03:43:52 UTC
HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applies to nomad/client/allocrunner/taskrunner/template.

https://www.hashicorp.com/blog/category/nomad
https://advisories.gitlab.com/advisory/advgo_github_com_hashicorp_nomad_client_allocrunner_taskrunner_template_GMS_2022_818.html


Note You need to log in before you can comment on or make changes to this bug.