Updated nats-server packages fix security vulnerability
Publication date: 13 Jun 2022Modification date: 13 Jun 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-24450
Description
NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature. (CVE-2022-24450)
References
SRPMS
8/core
- nats-server-2.1.9-1.1.mga8