← Back

CVE-2023-47090

nvd nist
Published: Oct 30, 2023Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0.

Affected (2)

Nats Server
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Linuxfoundation
From 2.10.0 to 2.10.2
From 2.2.0 to 2.9.23

References (6)

Source: cve@mitre.org
Mailing ListMitigation
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigation

Timeline

No history available yet.