MGASA-2022-0225

Source
https://advisories.mageia.org/MGASA-2022-0225.html
Import Source
https://advisories.mageia.org/MGASA-2022-0225.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2022-0225
Related
Published
2022-06-13T20:44:20Z
Modified
2022-06-13T19:53:15Z
Summary
Updated nats-server packages fix security vulnerability
Details

NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature. (CVE-2022-24450)

References
Credits

Affected packages

Mageia:8 / nats-server

Package

Name
nats-server
Purl
pkg:rpm/mageia/nats-server?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.9-1.1.mga8

Ecosystem specific

{
    "section": "core"
}