CVE-2021-37218 is a privilege escalation vulnerability affecting HashiCorp Nomad and Nomad Enterprise. It allows non-server agents with a valid certificate from the same CA to access server-only Raft RPC functionality. This vulnerability has a high CVSS score of 8.8, indicating a network-based attack with low complexity that can lead to high impact on confidentiality, integrity, and availability. While no active exploitation or public exploit code is currently reported, and community discussion is minimal, organizations using affected versions (prior to 1.0.10 and 1.1.4) should prioritize patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.10CPE matchmatch criteria | cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:* | ||
<= 1.0.10CPE matchmatch criteria | cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:* | ||
>= 1.1.1, < 1.1.4CPE matchmatch criteria | cpe:2.3:a:hashicorp:nomad:*:*:*:*:-:*:*:* | ||
>= 1.1.1, < 1.1.4CPE matchmatch criteria | cpe:2.3:a:hashicorp:nomad:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.