CVE-2024-7625
MEDIUMDescription
In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability.
Is your site exposed to CVE-2024-7625?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| hashicorp | nomad |
| hashicorp | nomad |
| hashicorp | nomad |
| hashicorp | nomad |
| hashicorp | nomad |
| hashicorp | nomad |
References
Frequently Asked Questions
What is CVE-2024-7625? +
How severe is CVE-2024-7625? +
What products are affected by CVE-2024-7625? +
How do I check if I'm vulnerable to CVE-2024-7625? +
Related Vulnerabilities
A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud …
A vulnerability exists in the Rockwell Automation Emulate3D™, which could be leveraged to execute a DLL Hijacking attack. The application …
Sitecore Experience Platform (XP) prior to 8.0 Initial Release (rev. 141212) and Content Management System (CMS) prior to 7.2 Update-3 …
An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform …
Netskope Client on Mac OS is impacted by a vulnerability in which the postinstall script does not properly validate the …
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit …