CVE-2021-41865
Last modified
CVE-2021-41865 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by submitting incomplete job specifications with a Consul mesh gateway and host networking mode. Fixed in 1.1.6.. EPSS estimates a 0.97% chance of exploitation in the next 30 days.
Description
HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by submitting incomplete job specifications with a Consul mesh gateway and host networking mode. Fixed in 1.1.6.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Nomad | >= 1.1.1, < 1.1.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-41865?
How severe is CVE-2021-41865?
How do I fix CVE-2021-41865?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-41859Rejected reason: This is unused.
- CVE-2021-4186Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 …7.5
- CVE-2021-41860Rejected reason: This is unused.
- CVE-2021-41861The Telegram application 7.5.0 through 7.8.0 for Android doe…3.3
- CVE-2021-41862AviatorScript through 5.2.7 allows code execution via an exp…9.8
- CVE-2021-41864prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the …7.8
- CVE-2021-41866MyBB before 1.8.28 allows stored XSS because the displayed T…5.4
- CVE-2021-41867An information disclosure vulnerability in OnionShare 2.3 be…5.3
- CVE-2021-41868OnionShare 2.3 before 2.4 allows remote unauthenticated atta…9.8
- CVE-2021-41869SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is …8.8
- CVE-2021-4187vim is vulnerable to Use After Free7.8
- CVE-2021-41870An issue was discovered in the firmware update form in Socom…8.8
Are you affected by CVE-2021-41865?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
