CVE-2020-28466
Denial of Service (DoS)
描述
This affects all versions of package github.com/nats-io/nats-server/server. Untrusted accounts are able to crash the server using configs that represent a service export/import cycles. Disclaimer from the maintainers: Running a NATS service which is exposed to untrusted users presents a heightened risk. Any remote execution flaw or equivalent seriousness, or denial-of-service by unauthenticated users, will lead to prompt releases by the NATS maintainers. Fixes for denial of service issues with no threat of remote execution, when limited to account holders, are likely to just be committed to the main development branch with no special attention. Those who are running such services are encouraged to build regularly from git.
如何修補 CVE-2020-28466
要修補 CVE-2020-28466,請將受影響套件升級到下列已修補版本。
- —升級至 2.2.0 或更新版本
- —升級至 2.2.0 或更新版本
- —未列出修補版本
- —升級至 2.2.0 或更新版本
- —升級至 2.2.0 或更新版本
CVE-2020-28466 正在被利用嗎?
低 — EPSS 為 3.7%,目前沒有觀察到大規模利用活動。
受影響套件(5)
- >= 2.0.0, < 2.2.0
- from 0, < 2.2.0
- from 0
- from 0, < 2.2.0
- from 0, < 2.2.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |