VendorsNatsnats_streaming_serverall versions
Vulnerabilities

Nats Nats Streaming Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2022-24450
NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.
Published 2022-02-08 · Modified
9.0EPSS 0.013
CVE-2022-26652
NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.
Published 2022-03-10 · Modified
6.5EPSS 0.023