GHSA-3f24-pcvm-5jqc
NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching
Quick fix
GHSA-3f24-pcvm-5jqc — github.com/nats-io/nats-server/v2: upgrade to the fixed version with the command below.
go get github.com/nats-io/nats-server/v2@v2.11.15Details
### Background
NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.
One authentication model supported is mTLS, deriving the NATS client identity from properties of the TLS Client Certificate.
### Problem Description
When using mTLS for client identity, with `verify_and_map` to derive a NATS identity from the client certificate's Subject DN, certain patterns of RDN would not be correctly enforced, allowing for authentication bypass.
This does require a valid certificate from a CA already trusted for client certificates, and `DN` naming patterns which the NATS maintainers consider highly unlikely.
So this is an unlikely attack. Nonetheless, administrators who have been very sophisticated in their `DN` construction patterns might conceivably be impacted.
### Affected Versions
Fixed in nats-server 2.12.6 & 2.11.15
### Workarounds
Developers should review their CA issuing practices.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.11.15go get github.com/nats-io/nats-server/v2@v2.11.152.12.0-RC.1Fixed in: 2.12.6go get github.com/nats-io/nats-server/v2@v2.12.60No fixed version published yet for github.com/nats-io/nats-server (go modules). Pin to a known-safe version or switch to an alternative.