VulnerabilityModified
CVE-2023-47090
NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass.
MEDIUM 6.5EPSS 0.66%
Does this matter?
Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.
Description
NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- linuxfoundation/nats-server
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2023/10/30/1Mailing List
- https://github.com/nats-io/nats-server/security/advisories/GHSA-fr2g-9hjm-wr23Vendor Advisory
- https://www.openwall.com/lists/oss-security/2023/10/13/2Mailing List, Mitigation
- http://www.openwall.com/lists/oss-security/2023/10/30/1Mailing List
- https://github.com/nats-io/nats-server/security/advisories/GHSA-fr2g-9hjm-wr23Vendor Advisory
- https://www.openwall.com/lists/oss-security/2023/10/13/2Mailing List, Mitigation
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.