CVE-2022-24450
08.02.2022, 02:15
NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.Enginsight
Vendor | Product | Version |
---|---|---|
nats | nats_server | 2.0.0 ≤ 𝑥 < 2.7.2 |
nats | nats_streaming_server | 0.15.0 ≤ 𝑥 < 0.24.1 |
𝑥
= Vulnerable software versions

Debian Releases
Common Weakness Enumeration