CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Linuxfoundation Nats3Nats Server Nats ServerNats Streaming ServerJun 17, 2026 Mar 10, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected. |
2Linuxfoundation Nats3Nats Server Nats ServerNats Streaming ServerJun 17, 2026 Feb 8, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature. |