References https://nvd.nist.gov/vuln/detail/CVE-2024-7625 https://www.cvedetails.com/cve-details.php?cve_id=CVE-2024-7625 https://github.com/advisories/GHSA-25qx-vfw2-fw8r https://vuldb.com/vuln/274715 https://discuss.hashicorp.com/t/hcsec-2024-15-nomad-vulnerable-to-allocation-directory-path-escape-through-archive-unpacking/68781 https://securityvulnerability.io/vulnerability/CVE-2024-7625 https://app.opencve.io/cve/CVE-2024-7625
Related VulnerabilitiesPoCCVE-2020-25864: HashiCorp Consul/Consul Enterprise <=1.9.4 - Cross-Site ScriptingPoCCVE-2022-29153: HashiCorp Consul/Consul Enterprise - Server-Side Request ForgeryPoChashicorp-consul-unauth: Hashicorp Consul API UnauthenticatedPoCexposed-nomad: Nomad - Exposed Jobsvault-unsealed-unauth: HashiCorp Vault API - ExposurePoChashicorp-consul-rce: Hashicorp Consul Services API - Remote Code Execution(CVE-2025-4922)Nomad基于前缀ACL策略规则应用错误及覆盖漏洞HashiCorp Vault Community Edition等 权限管理不当漏洞HashiCorp go-retryablehttp 日志信息泄露漏洞HashiCorp Vault 日志信息泄露漏洞HashiCorp Consul/Consul Enterprise 存在ssrf漏洞(CVE-2022-29153)