Source: nomad
Version: 0.10.5+dfsg1-3
Severity: important
Tags: security upstream
Forwarded: https://github.com/hashicorp/nomad/issues/9129
X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>

Hi,

The following vulnerability was published for nomad.

CVE-2020-27195[0]:
| HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client
| file sandbox feature can be subverted using either the template or
| artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2020-27195
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27195
[1] https://github.com/hashicorp/nomad/issues/9129
[2] 
https://github.com/hashicorp/nomad/commit/a8ea7c5f421297db434b45046fca7a9deef6df85

Regards,
Salvatore

Reply via email to