HashiCorp Nomad and Nomad Enterprise 0.3.0 through 1.0.17, 1.1.11, and 1.2.5 artifact download functionality has a race condition such that the Nomad client agent could download the wrong artifact into the wrong destination. This issue is fixed in 1.0.18, 1.1.12, and 1.2.6.
{
"github_reviewed": true,
"severity": "MODERATE",
"github_reviewed_at": "2022-03-18T18:21:52Z",
"nvd_published_at": "2022-02-14T14:15:00Z",
"cwe_ids": [
"CWE-362"
]
}