HashiCorp Nomad and Nomad Enterprise version 0.9.0 up to 0.12.5 client file sandbox feature can be subverted using either the template or artifact stanzas. Fixed in 0.12.6, 0.11.5, and 0.10.6
{
"versions": [
{
"introduced": "0.9.0"
},
{
"last_affected": "0.10.5"
},
{
"introduced": "0.9.0"
},
{
"last_affected": "0.10.5"
},
{
"introduced": "0.11.0"
},
{
"last_affected": "0.11.4"
},
{
"introduced": "0.11.0"
},
{
"last_affected": "0.11.4"
},
{
"introduced": "0.12.0"
},
{
"last_affected": "0.12.5"
},
{
"introduced": "0.12.0"
},
{
"last_affected": "0.12.5"
}
]
}