NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature. (CVE-2022-24450)
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2022-0225.json"