The vendor explicitly identifies these products or versions as containing the fix.
- nats-server2-12-main@aarch64 as a component of Red Hat Hardened Images
- nats-server2-12-main@src as a component of Red Hat Hardened Images
- nats-server2-12-main@x86_64 as a component of Red Hat Hardened Images
- nats-server2-14-main@aarch64 as a component of Red Hat Hardened Images
- nats-server2-14-main@src as a component of Red Hat Hardened Images
- nats-server2-14-main@x86_64 as a component of Red Hat Hardened Images
- Summary
- A flaw was found in NATS Server, a high-performance messaging system. This vulnerability allows a client to bypass normal authentication and connection restrictions by registering as a "no_auth_user" through a specific parser path. This occurs when the client's initial operation is not a standard connection request. The consequence is unauthorized access, potentially leading to information disclosure or other unauthorized actions within the messaging system.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
