VDB
Sign up
HIGH7.1

GHSA-jxxm-27vp-c3m5

NATS allows MQTT clients to bypass ACL checks

Quick fix

GHSA-jxxm-27vp-c3m5 — github.com/nats-io/nats-server/v2: upgrade to the fixed version with the command below.

go get github.com/nats-io/nats-server/v2@v2.11.15

Details

### Background

NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.

The nats-server provides an MQTT client interface.

### Problem Description

When using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing MQTT clients to bypass ACL checks for MQTT subjects.

### Affected Versions

Any version before v2.12.6 or v2.11.15

### Workarounds

None.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/nats-io/nats-server/v2
Introduced in: 0Fixed in: 2.11.15
Fixgo get github.com/nats-io/nats-server/v2@v2.11.15
Go/github.com/nats-io/nats-server/v2
Introduced in: 2.12.0-RC.1Fixed in: 2.12.6
Fixgo get github.com/nats-io/nats-server/v2@v2.12.6
Go/github.com/nats-io/nats-server
Introduced in: 0

No fixed version published yet for github.com/nats-io/nats-server (go modules). Pin to a known-safe version or switch to an alternative.

References