CVE-2022-26652: Arbitrary file write in nats-server
(updated )
NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.
References
- www.openwall.com/lists/oss-security/2022/03/10/1
- advisories.nats.io/CVE/CVE-2022-26652.txt
- github.com/advisories/GHSA-6h3m-36w8-hv68
- github.com/nats-io/nats-server/pull/2917
- github.com/nats-io/nats-server/releases
- github.com/nats-io/nats-server/releases/tag/v2.7.4
- github.com/nats-io/nats-server/security/advisories/GHSA-6h3m-36w8-hv68
- github.com/nats-io/nats-streaming-server/releases/tag/v0.24.3
- nvd.nist.gov/vuln/detail/CVE-2022-26652
Detect and mitigate CVE-2022-26652 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →