Incorrect authorization in NATS Streaming System Server and nats-server - CVE-2022-24450
Published: June 27, 2022 / Updated: June 30, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to misusing the "dynamically provisioned sandbox accounts" feature. A remote user can take advantage of its valid account and switch over to another existing account without further authentication to obtain the privileges of the System account.
Affected software
nats-server
Red Hat Advanced Cluster Management for Kubernetes
Beego
How to mitigate CVE-2022-24450
nats-server - update to 2.7.2
Beego - update to 2.0.7
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.4.3, 2.4.4, 2.4.5, 2.5.0, 2.5.1
External References
Related Security Bulletins
- Incorrect authorization in nats-server
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management 2.5
- beego update for nats-server
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2.4
- Multiple vulnerabilities in Red Hat Advanced Cluster Management for Kubernetes 2