Advisories ยป MGASA-2022-0225

Updated nats-server packages fix security vulnerability

Publication date: 13 Jun 2022
Modification date: 13 Jun 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-24450

Description

NATS nats-server before 2.7.2 has Incorrect Access Control. Any
authenticated user can obtain the privileges of the System account by
misusing the "dynamically provisioned sandbox accounts" feature.
(CVE-2022-24450)
                

References

SRPMS

8/core