Логотип exploitDog
bind:CVE-2023-47090
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-47090

Количество 5

Количество 5

ubuntu логотип

CVE-2023-47090

больше 2 лет назад

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-47090

больше 2 лет назад

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2023-47090

больше 2 лет назад

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-47090

больше 2 лет назад

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authent ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-fr2g-9hjm-wr23

больше 2 лет назад

NATS.io: Adding accounts for just the system account adds auth bypass

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-47090

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-47090

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-47090

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authent ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-fr2g-9hjm-wr23

NATS.io: Adding accounts for just the system account adds auth bypass

0%
Низкий
больше 2 лет назад

Уязвимостей на страницу