Skip to content
nats-serverGHSA-vpjc-4jcv-jc29

NATS nats-server allows directory traversal via unintended path to a management action

Critical9.8CVE-2022-28357 · Published Sep 19, 2023 · updated Aug 21, 2024

NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/nats-io/nats-server
Go
>= 2.2.0, < 2.7.42.7.4
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
CVE-2022-28357, GO-2023-2066

More nats-server advisories

All nats-server

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.