First published: Tue Sep 19 2023(Updated: )
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxfoundation Nats-server | >=2.2.0<=2.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-28357 is critical with a severity value of 9.8.
CVE-2022-28357 affects NATS nats-server versions 2.2.0 through 2.7.4.
CVE-2022-28357 is a directory traversal vulnerability in NATS nats-server that allows unauthorized access to management actions.
To fix CVE-2022-28357, update NATS nats-server to version 2.7.4 or later.
You can find more information about CVE-2022-28357 on the advisories page, the GitHub repository for nats-server, and the NVD website.