NATS-Server
Moderate fix2 remedies
cpe:2.3:a:nats:nats_server:*:*:*:*:*:*:*
Moderate fix2 remedies
- < 2.12.6
- < 2.11.15
A vulnerability exists in NATS-Server versions prior to 2.12.6 and 2.11.15, where Access Control Lists (ACLs) on message subjects were not enforced in the '$MQTT.>' namespace. This oversight allowed MQTT clients to circumvent ACL checks for MQTT-related subjects.
Exploitation of this vulnerability could lead to unauthorized access or actions on MQTT subjects, bypassing established ACL restrictions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.