The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://github.com/nats-io/nats-server/commits/master | third party advisory patch |
https://www.openwall.com/lists/oss-security/2020/11/02/2 | third party advisory mailing list |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT67XCLIIBYRT762SVFBYFFTQFVSM3SI/ | vendor advisory |