CVE-2022-28357: Path Traversal
Published Sep 19, 2023
·Updated
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
Affected Software
2 affected componentsFixes available
go/github.com/nats-io/nats-server>=2.2.0<2.7.4
2.7.4
linuxfoundation Nats-server>=2.2.0<=2.7.4
Event History
Sep 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Advisory Published
03:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2022-28357?
The severity of CVE-2022-28357 is critical with a severity value of 9.8.
2
How does CVE-2022-28357 affect NATS nats-server?
CVE-2022-28357 affects NATS nats-server versions 2.2.0 through 2.7.4.
3
What is the vulnerability description of CVE-2022-28357?
CVE-2022-28357 is a directory traversal vulnerability in NATS nats-server that allows unauthorized access to management actions.
4
How can I fix CVE-2022-28357?
To fix CVE-2022-28357, update NATS nats-server to version 2.7.4 or later.
5
Where can I find more information about CVE-2022-28357?
You can find more information about CVE-2022-28357 on the advisories page, the GitHub repository for nats-server, and the NVD website.