#VU64698 Incorrect authorization in nats-server - CVE-2022-24450
Published: June 27, 2022 / Updated: June 29, 2022
nats-server
NATS - The Cloud Native Messaging System
Description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to misusing the "dynamically provisioned sandbox accounts" feature. A remote user can take advantage of its valid account and switch over to another existing account without further authentication to obtain the privileges of the System account.