HIGH
NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams
Published Mar 10, 2022
6.5
HIGHCVSS 3.1
EPSS 2.34%
Description
NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.
Affected products
No data.
OR
- ≥ 2.2.0 · < 2.7.4
- ≥ 0.15.0 · < 0.24.3
No data.
No Red Hat product state for this CVE.
github.com/nats-io/nats-server/v2
Go
Introduced 2.2.0 Fixed 2.7.4github.com/nats-io/nats-streaming-server
Go
Introduced 0.15.0 Fixed 0.24.3github.com/nats-io/nats-server
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/nats-io/nats-server/v2 | 2.2.0 | 2.7.4 |
| Go | github.com/nats-io/nats-streaming-server | 0.15.0 | 0.24.3 |
| Go | github.com/nats-io/nats-server | 0 | not fixed |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- http://www.openwall.com/lists/oss-security/2022/03/10/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://advisories.nats.io/CVE/CVE-2022-26652.txt x_refsource_CONFIRMVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1345 Advisory
- https://github.com/advisories/GHSA-6h3m-36w8-hv68 Advisory
- https://github.com/nats-io/nats-server/pull/2917
- https://github.com/nats-io/nats-server/releases x_refsource_MISCRelease NotesThird Party Advisory
- https://github.com/nats-io/nats-server/releases/tag/v2.7.4
- https://github.com/nats-io/nats-server/security/advisories/GHSA-6h3m-36w8-hv68 x_refsource_CONFIRMThird Party Advisory
- https://github.com/nats-io/nats-streaming-server/releases/tag/v0.24.3
- https://nvd.nist.gov/vuln/detail/CVE-2022-26652
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2022/03/10/1 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://advisories.nats.io/CVE/CVE-2022-26652.txt | x_refsource_CONFIRMVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1345 | Advisory | |
| https://github.com/advisories/GHSA-6h3m-36w8-hv68 | Advisory | |
| https://github.com/nats-io/nats-server/pull/2917 | ||
| https://github.com/nats-io/nats-server/releases | x_refsource_MISCRelease NotesThird Party Advisory | |
| https://github.com/nats-io/nats-server/releases/tag/v2.7.4 | ||
| https://github.com/nats-io/nats-server/security/advisories/GHSA-6h3m-36w8-hv68 | x_refsource_CONFIRMThird Party Advisory | |
| https://github.com/nats-io/nats-streaming-server/releases/tag/v0.24.3 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-26652 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 10, 2022
Updated Aug 3, 2024
Reserved Mar 7, 2022
Link CVE-2022-26652
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-1345 GHSA-6H3M-36W8-HV68 Assigner mitre
Published Mar 10, 2022
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2022-1345