The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://github.com/nats-io/nats-server/commits/master | third party advisory patch |
http://www.openwall.com/lists/oss-security/2020/11/02/2 | third party advisory mailing list |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT67XCLIIBYRT762SVFBYFFTQFVSM3SI/ | vendor advisory |