https://seclists.org/oss-sec/2023/q4/88: NATS: 2023-01: Adding accounts for just the system account adds auth bypass
Published Oct 13, 2023
·Updated
Affected Software
2 affected components
NATS nats-server<2.2.0
NATS nats-server>=2.9.0<=2.9.22
Frequently Asked Questions
1
What is the severity of NATS: 2023-01?
The severity of NATS: 2023-01 has not been explicitly assigned yet, but it is classified as an authorization bypass vulnerability.
2
How do I fix NATS: 2023-01?
To fix NATS: 2023-01, upgrade to version 2.9.23 or 2.10.2 of the NATS server.
3
What is the impact of NATS: 2023-01?
The impact of NATS: 2023-01 allows unauthorized access by bypassing authentication mechanisms if only the system account is configured.
4
When was NATS: 2023-01 published?
NATS: 2023-01 was published on October 13, 2023.
5
Is there a CVE assigned to NATS: 2023-01?
A CVE for NATS: 2023-01 has been requested but has not yet been assigned.