CVE-2022-26652

NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nats:nats_server:*:*:*:*:*:*:*:*
cpe:2.3:a:nats:nats_streaming_server:*:*:*:*:*:*:*:*

History

18 Mar 2022, 01:44

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 6.5
CWE CWE-22
First Time Nats
Nats nats Streaming Server
Nats nats Server
CPE cpe:2.3:a:nats:nats_streaming_server:*:*:*:*:*:*:*:*
cpe:2.3:a:nats:nats_server:*:*:*:*:*:*:*:*
References (CONFIRM) https://advisories.nats.io/CVE/CVE-2022-26652.txt - (CONFIRM) https://advisories.nats.io/CVE/CVE-2022-26652.txt - Vendor Advisory
References (CONFIRM) https://github.com/nats-io/nats-server/security/advisories/GHSA-6h3m-36w8-hv68 - (CONFIRM) https://github.com/nats-io/nats-server/security/advisories/GHSA-6h3m-36w8-hv68 - Third Party Advisory
References (MLIST) http://www.openwall.com/lists/oss-security/2022/03/10/1 - (MLIST) http://www.openwall.com/lists/oss-security/2022/03/10/1 - Mailing List, Third Party Advisory
References (MISC) https://github.com/nats-io/nats-server/releases - (MISC) https://github.com/nats-io/nats-server/releases - Release Notes, Third Party Advisory

10 Mar 2022, 17:53

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-10 17:47

Updated : 2023-12-10 14:22


NVD link : CVE-2022-26652

Mitre link : CVE-2022-26652

CVE.ORG link : CVE-2022-26652


JSON object : View

Products Affected

nats

  • nats_server
  • nats_streaming_server
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')