First published: Fri Nov 06 2020(Updated: )
The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxfoundation Nats-server | <2.1.9 | |
Fedoraproject Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26521 is a vulnerability in the JWT library in NATS nats-server before version 2.1.9 that allows a denial of service through a nil dereference in Go code.
The severity of CVE-2020-26521 is high, with a CVSS score of 7.5.
The Linuxfoundation NATS nats-server version up to exclusive 2.1.9 and Fedora 33 are affected by CVE-2020-26521.
To fix the CVE-2020-26521 vulnerability, update the NATS nats-server to version 2.1.9 or later.
You can find more information about CVE-2020-26521 at the following references: [1] http://www.openwall.com/lists/oss-security/2020/11/02/2, [2] https://github.com/nats-io/nats-server/commits/master, [3] https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VT67XCLIIBYRT762SVFBYFFTQFVSM3SI/