https://seclists.org/oss-sec/2025/q2/29: CVE-2025-30215: nats-server: Missing access controls for JS API
Published Apr 8, 2025
·Updated
Affected Software
1 affected component
NATS nats-server>=2.10.27<=2.11.1
Frequently Asked Questions
1
What is the severity of CVE-2025-30215?
CVE-2025-30215 has been classified as a medium-severity vulnerability.
2
How do I fix CVE-2025-30215?
To fix CVE-2025-30215, upgrade to nats-server version 2.11.1 or 2.10.27 or later.
3
What is the impact of CVE-2025-30215?
CVE-2025-30215 allows unauthorized access to the JavaScript API in multi-tenancy environments.
4
Is CVE-2025-30215 exploitable remotely?
Yes, CVE-2025-30215 can be exploited remotely due to the missing access controls.
5
When was CVE-2025-30215 published?
CVE-2025-30215 was published on April 8, 2025.