MEDIUM 6.5 Go
NATS Server and Streaming Server fails to enforce negative user permissions, may allow denied subjects
GHSA-2h2x-8hh2-mfq8 · CVE-2022-29946 · GO-2024-2980
Published · Modified
Description
NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one scenario. By using a queue subscription on the wildcard, an attacker could exploit this vulnerability to allow denied subjects.
Ready to move
Start Securing
Free, no credit card | First findings in minutes