CVE-2020-10944: Hashicorp Nomad
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could cause arbitrary JavaScript to execute in the web UI. Fixed in 0.10.5.
Affected products
- Hashicorp Nomad: from 0.3, before 0.10.5 (fixed in 0.10.5)
Published 2020-04-28. Last modified 2026-06-17.