HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6
{
"nvd_published_at": null,
"github_reviewed_at": "2021-05-12T21:58:02Z",
"cwe_ids": [
"CWE-416"
],
"severity": "CRITICAL",
"github_reviewed": true
}