Описание
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled could crash the server during the pre-authentication leafnode handshake by sending repeated leafnode INFO protocol messages before authentication and account setup completed. This issue is fixed in versions 2.12.8 and 2.11.17.
A flaw was found in NATS Server, a high-performance messaging system. An unauthenticated attacker with network access to a leafnode listener, where compression is enabled, could exploit this vulnerability. By sending repeated leafnode INFO protocol messages during the pre-authentication handshake, the attacker can cause the server to crash. This leads to a Denial of Service (DoS), making the server unavailable to legitimate users.
Отчет
This is an Important denial of service vulnerability in NATS Server. An unauthenticated remote attacker with network access to a leafnode listener, configured with compression enabled, could repeatedly send INFO protocol messages during the pre-authentication handshake. This action would cause the NATS server to crash, leading to a denial of service for legitimate users.
Меры по смягчению последствий
To reduce exposure, disable compression on NATS Server leafnode listeners if not strictly required for your environment. Alternatively, implement network access controls to restrict connectivity to leafnode listeners to only trusted clients. This limits the ability of unauthenticated peers to initiate the vulnerable handshake.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Hardened Images | nats-server2.12 | Not affected | ||
| Red Hat Hardened Images | nats-server2.14 | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.11.17, an unauthenticated peer with network access to a leafnode listener with compression enabled could crash the server during the pre-authentication leafnode handshake by sending repeated leafnode INFO protocol messages before authentication and account setup completed. This issue is fixed in versions 2.12.8 and 2.11.17.
NATS Server: Pre-auth server crash via double INFO in leafnode handshake
NATS Server is a high-performance server for NATS.io, the cloud and ed ...
EPSS
7.5 High
CVSS3