blob: c31ccbff628de8e48adb38d7d5eee2c8b9185d02 [file] [log] [blame]
id: GO-2024-2980
modules:
- module: github.com/nats-io/nats-server
vulnerable_at: 1.4.1
- module: github.com/nats-io/nats-server/v2
versions:
- fixed: 2.8.2
vulnerable_at: 2.8.1
- module: github.com/nats-io/nats-streaming-server
versions:
- fixed: 0.24.6
vulnerable_at: 0.24.5
summary: |-
NATS Server and Streaming Server fails to enforce negative user permissions, may
allow denied subjects in github.com/nats-io/nats-server
cves:
- CVE-2022-29946
ghsas:
- GHSA-2h2x-8hh2-mfq8
references:
- advisory: https://github.com/advisories/GHSA-2h2x-8hh2-mfq8
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2022-29946
- web: https://github.com/nats-io/advisories/blob/main/CVE/CVE-2022-29946.txt
source:
id: GHSA-2h2x-8hh2-mfq8
created: 2024-07-12T16:33:37.628744846Z
review_status: UNREVIEWED