Описание
NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one scenario. By using a queue subscription on the wildcard, an attacker could exploit this vulnerability to allow denied subjects.
A flaw was found in the NATS Server and NATS Streaming Server. Affected versions of this package could allow a remote attacker to bypass security restrictions due to a failure to enforce negative user permissions in one scenario. By using a queue subscription on the wildcard, an attacker could exploit this vulnerability to allow denied subjects.
Меры по смягчению последствий
Recraft user permission rules to only add access, never deny it.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift AI (RHOAI) | odh-ml-pipelines-api-server-v2-container | Affected | ||
| Red Hat OpenShift AI (RHOAI) | odh-ml-pipelines-driver-container | Affected | ||
| Red Hat OpenShift AI (RHOAI) | odh-ml-pipelines-launcher-container | Affected | ||
| Red Hat OpenShift AI (RHOAI) | odh-ml-pipelines-persistenceagent-v2-container | Affected | ||
| Red Hat OpenShift AI (RHOAI) | odh-ml-pipelines-scheduledworkflow-v2-container | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-contour-rhel8 | Not affected | ||
| Red Hat Openshift Container Storage 4 | ocs4/mcg-rhel8-operator | Out of support scope | ||
| Red Hat Openshift Container Storage 4 | ocs4/ocs-must-gather-rhel8 | Out of support scope | ||
| Red Hat Openshift Container Storage 4 | ocs4/ocs-rhel8-operator | Out of support scope | ||
| Red Hat Trusted Profile Analyzer | trusted-content-tenant/trustification-guac | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one scenario. By using a queue subscription on the wildcard, an attacker could exploit this vulnerability to allow denied subjects.
NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one scenario. By using a queue subscription on the wildcard, an attacker could exploit this vulnerability to allow denied subjects.
NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 co ...
NATS Server and Streaming Server fails to enforce negative user permissions, may allow denied subjects
EPSS
5.4 Medium
CVSS3