Vulnerability Details CVE-2019-14802
HashiCorp Nomad 0.5.0 through 0.9.4 (fixed in 0.9.5) reveals unintended environment variables to the rendering task during template rendering, aka GHSA-6hv3-7c34-4hx8. This applies to nomad/client/allocrunner/taskrunner/template.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 49.6%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2019-14802
-
cpe:2.3:a:hashicorp:nomad:0.5.0
-
cpe:2.3:a:hashicorp:nomad:0.5.1
-
cpe:2.3:a:hashicorp:nomad:0.5.2
-
cpe:2.3:a:hashicorp:nomad:0.5.3
-
cpe:2.3:a:hashicorp:nomad:0.5.4
-
cpe:2.3:a:hashicorp:nomad:0.5.5
-
cpe:2.3:a:hashicorp:nomad:0.5.6
-
cpe:2.3:a:hashicorp:nomad:0.6.0
-
cpe:2.3:a:hashicorp:nomad:0.6.1
-
cpe:2.3:a:hashicorp:nomad:0.6.2
-
cpe:2.3:a:hashicorp:nomad:0.6.3
-
cpe:2.3:a:hashicorp:nomad:0.7.0
-
cpe:2.3:a:hashicorp:nomad:0.7.1
-
cpe:2.3:a:hashicorp:nomad:0.8.0
-
cpe:2.3:a:hashicorp:nomad:0.8.1
-
cpe:2.3:a:hashicorp:nomad:0.8.2
-
cpe:2.3:a:hashicorp:nomad:0.8.3
-
cpe:2.3:a:hashicorp:nomad:0.8.4
-
cpe:2.3:a:hashicorp:nomad:0.8.5
-
cpe:2.3:a:hashicorp:nomad:0.8.6
-
cpe:2.3:a:hashicorp:nomad:0.8.7
-
cpe:2.3:a:hashicorp:nomad:0.9.0
-
cpe:2.3:a:hashicorp:nomad:0.9.1
-
cpe:2.3:a:hashicorp:nomad:0.9.2
-
cpe:2.3:a:hashicorp:nomad:0.9.3
-
cpe:2.3:a:hashicorp:nomad:0.9.4