Описание
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send account-scoped connection monitoring requests could crash the server by supplying Connz pagination Offset and Limit values that overflowed internal arithmetic before the response window was safely bounded. This issue is fixed in versions 2.14.3 and 2.12.12.
A flaw was found in NATS Server. A client with the ability to send account-scoped connection monitoring requests could crash the server. This is achieved by providing pagination offset and limit values that cause an arithmetic overflow, leading to a Denial of Service (DoS).
Отчет
CVE.org and NVD independently assess this issue at different severities than Red Hat because CVE.org uses a Changed scope (S:C) in its CVSS vector, treating the crash as impacting components beyond the NATS Server process itself. Red Hat, consistent with NVDs own scoring, assesses the impact as scoped to the NATS Server process (Scope Unchanged), resulting in a CVSS score of 6.5 and a Moderate impact rating. Only account-scoped connection-monitoring requests can trigger the arithmetic overflow, and no Red Hat product runs an externally-reachable, unauthenticated NATS Server monitoring endpoint by default.
Меры по смягчению последствий
Upstream mitigation: restrict publish access to system request subjects (e.g. .REQ.ACCOUNT.*.CONNZ) for untrusted clients, and avoid no-auth NATS deployments where untrusted clients can publish to system monitoring request subjects. Upgrading to nats-server 2.14.3 or 2.12.12 (or later) fully resolves the issue.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Multicluster Global Hub | multicluster-globalhub/multicluster-globalhub-grafana-rhel9 | Fix deferred | ||
| Red Hat Ceph Storage 5 | rhceph/snmp-notifier-rhel8 | Fix deferred | ||
| Red Hat Ceph Storage 6 | rhceph/snmp-notifier-rhel9 | Fix deferred | ||
| Red Hat Ceph Storage 7 | rhceph/snmp-notifier-rhel9 | Fix deferred | ||
| Red Hat Ceph Storage 8 | rhceph/snmp-notifier-rhel9 | Fix deferred | ||
| Red Hat Ceph Storage 9 | rhceph/snmp-notifier-rhel10 | Fix deferred | ||
| Red Hat Hardened Images | nats-server2.12 | Not affected | ||
| Red Hat Hardened Images | nats-server2.14 | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/oc-mirror-plugin-rhel9 | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send account-scoped connection monitoring requests could crash the server by supplying Connz pagination Offset and Limit values that overflowed internal arithmetic before the response window was safely bounded. This issue is fixed in versions 2.14.3 and 2.12.12.
NATS Server: Remote crash via integer overflow in Connz pagination
NATS Server is a high-performance server for NATS.io, the cloud and ed ...
EPSS
6.5 Medium
CVSS3