CVE-2022-24450
EUVD-2022-100008.02.2022, 02:15
NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nats | nats_server | 2.0.0 ≤ 𝑥 < 2.7.2 |
| nats | nats_streaming_server | 0.15.0 ≤ 𝑥 < 0.24.1 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration