REDHAT-BUG-2451446: High severity NATS NATS Server vulnerability
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the $MQTT.> namespace, allowing MQTT clients to bypass ACL checks for MQTT subjects. Versions 2.11.15 and 2.12.6 contain a fix. No known workarounds are available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NATS-Serverto a version that resolves this vulnerability.Fixed in 2.11.15 - Upgrade
Upgrade
NATS-Serverto a version that resolves this vulnerability.Fixed in 2.12.6
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2451446?
The severity of REDHAT-BUG-2451446 is high, rated at 7.
How do I fix REDHAT-BUG-2451446?
To fix REDHAT-BUG-2451446, update your NATS Server to version 2.11.15 or 2.12.6 or later.
What vulnerability does REDHAT-BUG-2451446 describe?
REDHAT-BUG-2451446 describes a vulnerability where ACLs were not applied correctly in the $MQTT.> namespace, allowing MQTT clients to bypass ACL checks.
What are the affected versions of the NATS Server in REDHAT-BUG-2451446?
The affected versions of the NATS Server in REDHAT-BUG-2451446 are prior to versions 2.11.15 and 2.12.6.
What is the impact of REDHAT-BUG-2451446 on MQTT clients?
The impact of REDHAT-BUG-2451446 is that MQTT clients can bypass ACL checks for MQTT subjects, potentially leading to unauthorized access.