CVE-2022-24450 PUBLISHED

NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.

EPSS 0.53% · 67.0th percentile

Risk Scores

EPSS Score
0.53%
67.0th percentile

Affected Products

VendorProductVersions
Bitnaminats2.0.0
Bitnaminats2.0.0

Timeline

References

Open in Interactive Console →