NATS nats-server before 2.7.2 has Incorrect Access Control. Any authenticated user can obtain the privileges of the System account by misusing the "dynamically provisioned sandbox accounts" feature.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-02-08T01:14:48

Updated: 2022-02-08T01:14:48

Reserved: 2022-02-04T00:00:00


Link: CVE-2022-24450

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-02-08T02:15:06.687

Modified: 2023-08-08T14:22:24.967


Link: CVE-2022-24450

JSON object: View

cve-icon Redhat Information

No data.

CWE