Mageia 2022-0225: nats-server security update
Summary
NATS nats-server before 2.7.2 has Incorrect Access Control. Any
authenticated user can obtain the privileges of the System account by
misusing the "dynamically provisioned sandbox accounts" feature.
(CVE-2022-24450)
References
- https://bugs.mageia.org/show_bug.cgi?id=30013
- https://advisories.nats.io/CVE/CVE-2022-24450.txt
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24450
Resolution
MGASA-2022-0225 - Updated nats-server packages fix security vulnerability
SRPMS
- 8/core/nats-server-2.1.9-1.1.mga8