Improper Authorization in nats-server



Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2025-30215
CWE-ID CWE-285
Exploitation vector Network
Public exploit Public exploit code for vulnerability #1 is available.
Vulnerable software
nats-server
Server applications / Other server solutions

Vendor NATS - The Cloud Native Messaging System

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Improper Authorization

EUVDB-ID: #VU107481

Risk: Medium

CVSSv4.0: 5.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:H/E:P/U:Green]

CVE-ID: CVE-2025-30215

CWE-ID: CWE-285 - Improper Authorization

Exploit availability: Yes

Description

The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to the failure to authorize certain Jetstream admin APIs. A remote user can perform certain administrative actions on any JS asset in any other account.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

nats-server: 2.2.0 - 2.11.0 RC.5

CPE2.3 External links

https://www.openwall.com/lists/oss-security/2025/04/08/5
https://advisories.nats.io/CVE/secnote-2025-01.txt
https://github.com/nats-io/nats-server/security/advisories/GHSA-fhg8-qxh5-7q3w


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.



###SIDEBAR###