https://seclists.org/oss-sec/2023/q4/197: NATS: 2023-02: nkeys: xkeys Seal encryption used fixed key for all encryption
Published Oct 31, 2023
·Updated
Affected Software
2 affected components
NATS nkeys<0.4.6
NATS nats-server>=2.10.0
Frequently Asked Questions
1
What is the severity of CVE-2023-46129?
CVE-2023-46129 is rated as a high severity vulnerability due to the use of a fixed key for all encryption in nkeys.
2
How do I fix CVE-2023-46129?
To fix CVE-2023-46129, upgrade to nkeys version 0.4.6 or nats-server version 2.10.4.
3
What impact does CVE-2023-46129 have on NATS nkeys?
CVE-2023-46129 may compromise the confidentiality of encrypted data due to the fixed key used in xkeys Seal encryption.
4
When was CVE-2023-46129 published?
CVE-2023-46129 was published on October 31, 2023.
5
What products are affected by CVE-2023-46129?
CVE-2023-46129 affects NATS nkeys and NATS nats-server software.