Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2026-33222

5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, if developers have configured users to have limited JetStream restore permissions, temporarily remove those permissions.

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2026-33222

5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, if developers have configured users to have limited JetStream restore permissions, temporarily remove those permissions.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2026-33222

5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, if developers have configured users to have limited JetStream restore permissions, temporarily remove those permissions.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2026-33222

5 месяцев назад

NATS-Server is a High-Performance server for NATS.io, a cloud and edge ...

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-9983-vrx2-fg9c

5 месяцев назад

NATS JetStream has an authorization bypass through its Management API

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-33222

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, if developers have configured users to have limited JetStream restore permissions, temporarily remove those permissions.

CVSS3: 4.9
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-33222

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, if developers have configured users to have limited JetStream restore permissions, temporarily remove those permissions.

CVSS3: 4.9
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-33222

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, if developers have configured users to have limited JetStream restore permissions, temporarily remove those permissions.

CVSS3: 4.9
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-33222

NATS-Server is a High-Performance server for NATS.io, a cloud and edge ...

CVSS3: 4.9
0%
Низкий
5 месяцев назад
github логотип
GHSA-9983-vrx2-fg9c

NATS JetStream has an authorization bypass through its Management API

CVSS3: 4.9
0%
Низкий
5 месяцев назад

Уязвимостей на страницу