Описание
NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| nats-server | not-affected | package |
Примечания
https://advisories.nats.io/CVE/CVE-2022-26652.txt
https://github.com/nats-io/nats-server/security/advisories/GHSA-6h3m-36w8-hv68
http://www.openwall.com/lists/oss-security/2022/03/10/1
EPSS
Процентиль: 71%
0.00684
Низкий
Связанные уязвимости
CVSS3: 6.5
nvd
почти 4 года назад
NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.
EPSS
Процентиль: 71%
0.00684
Низкий