#VU64698 Incorrect authorization in nats-server - CVE-2022-24450

 

#VU64698 Incorrect authorization in nats-server - CVE-2022-24450

Published: June 27, 2022 / Updated: June 29, 2022


Vulnerability identifier: #VU64698
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-24450
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
nats-server
Software vendor:
NATS - The Cloud Native Messaging System

Description

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to misusing the "dynamically provisioned sandbox accounts" feature. A remote user can take advantage of its valid account and switch over to another existing account without further authentication to obtain the privileges of the System account.


Remediation

Install update from vendor's website.

External links