CVE-2021-3127

HIGH7.5EPSS 0.29%

Duplicate Advisory: Incorrect Access Control in github.com/nats-io/jwt and github.com/nats-io/nats-server/v2

Published: 2/15/2022Modified: 2/4/2026
Also known as:GHSA-62mh-w5cv-p88cGHSA-9r5x-fjv3-q6h4GHSA-j756-f273-xhp4BIT-nats-2021-3127CGA-3xwf-56gh-qxqqGO-2022-0386

Description

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-62mh-w5cv-p88c (for github.com/nats-io/jwt) and GHSA-j756-f273-xhp4 (for github.com/nats-io/nats-server). This link is maintained to preserve external references. ## Original Description NATS Server (github.com/nats-io/nats-server/v2/server) 2.x before 2.2.0 and JWT library (github.com/nats-io/jwt/v2) before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.

Affected packages (10)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References (11)