NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "2.0.0-209"
}
],
"vendor_product": "linuxfoundation:nats.js",
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:linuxfoundation:nats.js:*:*:*:*:*:node.js:*:*"
]
},
{
"vendor_product": "linuxfoundation:nats.ws",
"cpes": [
"cpe:2.3:a:linuxfoundation:nats.ws:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "1.0.0-111"
}
],
"source": "CPE_RANGE"
}
]
}{
"cpe": "cpe:2.3:a:linuxfoundation:nats.deno:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.0.0-9"
}
],
"source": "CPE_RANGE"
}