Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2023-47090

почти 3 года назад

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-47090

почти 3 года назад

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-47090

почти 3 года назад

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-47090

почти 3 года назад

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authent ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-fr2g-9hjm-wr23

почти 3 года назад

NATS.io: Adding accounts for just the system account adds auth bypass

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-47090

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-47090

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
msrc логотип
CVE-2023-47090

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-47090

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authent ...

CVSS3: 6.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-fr2g-9hjm-wr23

NATS.io: Adding accounts for just the system account adds auth bypass

1%
Низкий
почти 3 года назад

Уязвимостей на страницу