NATS-Server
cpe:2.3:a:nats:nats_server:*:*:*:*:*:*:*
- <= 2.12.5
- <= 2.11.14
A vulnerability in NATS-Server versions through 2.11.14 and 2.12.5 allows for hijacking of sessions and messages via manipulation of the MQTT Client ID. This issue arises in the server's MQTT client interface, where improper handling of Client IDs can lead to unauthorized access to sessions and messages.
Exploitation of this vulnerability could result in unauthorized access to sessions and messages, allowing for interception or manipulation of the communication.
Users can upgrade to NATS-Server versions 2.12.6 or 2.11.15 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.