NATS-Server
cpe:2.3:a:nats:nats_server:*:*:*:*:*:*:*
- <= 2.12.5
- <= 2.11.14
A vulnerability exists in NATS-Server versions prior to 2.11.15 and 2.12.6, allowing identity spoofing through the Nats-Request-Info header. This header is intended to guarantee identity, but the removal of the header from incoming messages was not completely effective. As a result, an attacker with valid credentials for any regular client interface could impersonate their identity to services that depend on this header.
Exploitation of this vulnerability allows for identity spoofing, where an attacker can misrepresent themselves to services that rely on the Nats-Request-Info header for identity verification.
Users can upgrade to NATS-Server versions 2.12.6 or 2.11.15 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.