VDB
CVE-2022-24450
CVE-2022-24450
PUBLISHED
NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.
EPSS 0.65% · 71.4th percentile
Risk Scores
EPSS Score
0.65%
71.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | nats | 2.0.0 |
| Bitnami | nats | 2.0.0 |
Exploit Intelligence
- probe_messaging.go (github-poc)
- probe_messaging.go (github-poc)
- probe_messaging.go (github-poc)
- probe_messaging.go (github-poc)
- probe_messaging.go (github-poc)
- probe_messaging.go (github-poc)
- probe_messaging.go (github-poc)
- probe_messaging.go (github-poc)
- probe_messaging.go (github-poc)
Timeline
- Feb 8, 2022 CVE Published
- Feb 8, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 24, 2022 EPSS Score
- Jul 16, 2022 EPSS Score
- Sep 7, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 5, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Jul 18, 2023 EPSS Score