DirectorySecurity Advisories
Sign In
Security Advisories

CGA-wg3j-593x-7xrc

Published

Last updated

https://images.chainguard.dev/security/CGA-wg3j-593x-7xrc
Package

nats-server

Latest Update
Not affected
Aliases
  • CVE-2021-3127
  • GHSA-62mh-w5cv-p88c
  • GHSA-9r5x-fjv3-q6h4

Severity

7.5

High

CVSS V3

Summary

Duplicate Advisory: Incorrect Access Control in github.com/nats-io/jwt and github.com/nats-io/nats-server/v2

Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-62mh-w5cv-p88c (for github.com/nats-io/jwt) and GHSA-j756-f273-xhp4 (for github.com/nats-io/nats-server). This link is maintained to preserve external references.

Original Description

NATS Server (github.com/nats-io/nats-server/v2/server) 2.x before 2.2.0 and JWT library (github.com/nats-io/jwt/v2) before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images