Incorrect authorization in NATS Streaming System Server and nats-server - CVE-2022-24450

 

Incorrect authorization in NATS Streaming System Server and nats-server - CVE-2022-24450

Published: June 27, 2022 / Updated: June 30, 2026


Vulnerability identifier: #VU64698
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24450
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to misusing the "dynamically provisioned sandbox accounts" feature. A remote user can take advantage of its valid account and switch over to another existing account without further authentication to obtain the privileges of the System account.


Affected software

NATS Streaming System Server
nats-server
Red Hat Advanced Cluster Management for Kubernetes
Beego

How to mitigate CVE-2022-24450

Install update from vendor's website.

NATS Streaming System Server - update to 0.24.1
nats-server - update to 2.7.2
Beego - update to 2.0.7
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.4.3, 2.4.4, 2.4.5, 2.5.0, 2.5.1

External References

Related Security Bulletins