CVE-2022-24686
Nomad vulnerability analysis and mitigation

Overview

The vulnerability CVE-2022-24686 affects HashiCorp Nomad and Nomad Enterprise versions 0.3.0 through 1.0.17, 1.1.11, and 1.2.5. This vulnerability involves a race condition in the artifact download functionality where the Nomad client agent could potentially download the wrong artifact into the wrong destination. The issue was discovered and fixed in versions 1.0.18, 1.1.12, and 1.2.6 (HashiCorp Discuss).

Technical details

The vulnerability stems from an unsafe implementation of the go-getter library used for downloading artifacts as defined in the job definitions' artifact stanza. The issue was identified using the builtin go test race detector, which revealed that the go-getter client was being used in an unsafe manner when shared between goroutines. The vulnerability has been assigned a CVSS score of 5.9 (MEDIUM) with a vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N (NetApp Security).

Impact

If successfully exploited, this vulnerability could allow an attacker with job submission capabilities to impact another allocation, resulting in the client placing incorrect artifacts in wrong destinations. However, reliable exploitation in a live cluster is considered difficult as it would require precise timing of two artifact downloads outside of the attacker's own job submission (HashiCorp Discuss).

Mitigation and workarounds

Users are advised to upgrade to Nomad or Nomad Enterprise versions 1.0.18, 1.1.12, and 1.2.6 or newer to address this vulnerability. The fix involves modifications to Nomad's logic to prevent the race condition from occurring (HashiCorp Discuss).

Additional resources


SourceThis report was generated using AI

Related Nomad vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-4922HIGH8.1
  • NomadNomad
  • cpe:2.3:a:hashicorp:nomad
NoYesJun 11, 2025
CVE-2025-3744HIGH7.6
  • NomadNomad
  • cpe:2.3:a:hashicorp:nomad
NoYesMay 13, 2025
CVE-2025-0937HIGH7.1
  • NomadNomad
  • cpe:2.3:a:hashicorp:nomad
NoYesFeb 12, 2025
CVE-2025-1296MEDIUM6.5
  • NomadNomad
  • github.com/hashicorp/nomad
NoYesMar 10, 2025
CVE-2024-12678MEDIUM6.5
  • NomadNomad
  • github.com/hashicorp/nomad
NoYesDec 20, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management