CVE-2026-33222
MEDIUM4.9EPSS 0.01%NATS JetStream has an authorization bypass through its Management API
發布日:2026/3/24修改日:2026/3/27
描述
### Background NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing. The persistent storage feature, JetStream, has a management API which has many features, amongst which are backup and restore. ### Problem Description Users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. ### Affected Versions Any version before v2.12.6 or v2.11.15 ### Workarounds If developers have configured users to have limited JetStream restore permissions, temporarily remove those permissions.
受影響套件(6)
- Bitnami/natsfrom 0, < 2.11.15, >= 2.12.0, < 2.12.6
- Debian/nats-serverfrom 0
- Go/github.com/nats-io/nats-serverfrom 0
- Go/github.com/nats-io/nats-serverfrom 0
- Go/github.com/nats-io/nats-server/v2from 0, < 2.11.15
- Go/github.com/nats-io/nats-server/v2from 0, < 2.11.15, >= 2.12.0-RC.1, < 2.12.6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.9 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N |