NATS-Server
cpe:2.3:a:nats:nats_server:*:*:*:*:*:*:*
- >= 2.11.0, <= 2.11.14
- <= 2.12.5
A vulnerability in NATS-Server versions 2.11.0 prior to 2.11.15 and 2.12.0 prior to 2.12.6 allows clients using message tracing headers to redirect trace messages to arbitrary subjects, including those the client is not authorized to publish to. The issue arises because the payload, while a valid trace message, is not selected by the client. This vulnerability could lead to unauthorized message delivery on the NATS messaging system.
Exploitation of this vulnerability could result in unauthorized message tracing redirection, allowing trace messages to be sent to subjects without proper publish permissions.
Users can upgrade to NATS-Server versions 2.11.15 or 2.12.6 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.