Описание
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an unauthenticated client with access to the WebSocket listener to reach uninitialized MQTT state and crash the server process. This issue is fixed in versions 2.14.3 and 2.12.12.
A flaw was found in NATS Server. An unauthenticated client with access to the WebSocket listener could exploit a vulnerability where requests for the MQTT-over-WebSocket path were incorrectly routed into MQTT handling, even when MQTT was not configured. This allowed the client to access uninitialized MQTT state, leading to a server process crash. This can result in a Denial of Service (DoS) for the NATS Server.
Отчет
This Moderate flaw in NATS Server allows an unauthenticated remote attacker to cause a denial of service. The vulnerability arises from incorrect routing of WebSocket requests to uninitialized MQTT handling, even when MQTT is not configured, leading to a server crash. This impacts the availability of NATS Server deployments that expose a WebSocket listener, as it does not require specific MQTT configuration to exploit.
Меры по смягчению последствий
To mitigate this issue, restrict network access to the NATS Server's WebSocket listener to trusted clients only using firewall rules. If the WebSocket listener is not required, it can be disabled in the NATS Server configuration. Disabling the WebSocket listener may impact services that rely on WebSocket connectivity to the NATS Server. After making configuration changes, ensure to restart the NATS Server process for the changes to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Hardened Images | nats-server2.12 | Not affected | ||
| Red Hat Hardened Images | nats-server2.14 | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.8 Medium
CVSS3
Связанные уязвимости
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an unauthenticated client with access to the WebSocket listener to reach uninitialized MQTT state and crash the server process. This issue is fixed in versions 2.14.3 and 2.12.12.
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an unauthenticated client with access to the WebSocket listener to reach uninitialized MQTT state and crash the server process. This issue is fixed in versions 2.14.3 and 2.12.12.
NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled
NATS Server is a high-performance server for NATS.io, the cloud and ed ...
EPSS
6.8 Medium
CVSS3