HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.
{
"github_reviewed_at": "2026-01-05T14:59:35Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-610"
],
"github_reviewed": true,
"nvd_published_at": "2024-07-23T01:15:09Z"
}