Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9983-vrx2-fg9c

Опубликовано: 24 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.9

Описание

NATS JetStream has an authorization bypass through its Management API

Background

NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.

The persistent storage feature, JetStream, has a management API which has many features, amongst which are backup and restore.

Problem Description

Users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them.

Affected Versions

Any version before v2.12.6 or v2.11.15

Workarounds

If developers have configured users to have limited JetStream restore permissions, temporarily remove those permissions.

Пакеты

Наименование

github.com/nats-io/nats-server/v2

go
Затронутые версииВерсия исправления

< 2.11.15

2.11.15

Наименование

github.com/nats-io/nats-server/v2

go
Затронутые версииВерсия исправления

>= 2.12.0-RC.1, < 2.12.6

2.12.6

Наименование

github.com/nats-io/nats-server

go
Затронутые версииВерсия исправления

Отсутствует

EPSS

Процентиль: 23%
0.00306
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 4.9
ubuntu
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, if developers have configured users to have limited JetStream restore permissions, temporarily remove those permissions.

CVSS3: 4.9
redhat
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, if developers have configured users to have limited JetStream restore permissions, temporarily remove those permissions.

CVSS3: 4.9
nvd
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, if developers have configured users to have limited JetStream restore permissions, temporarily remove those permissions.

CVSS3: 4.9
debian
5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge ...

EPSS

Процентиль: 23%
0.00306
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-285