VDB
Sign up
MEDIUM4.2

GHSA-3f24-pcvm-5jqc

NATS has mTLS verify_and_map authentication bypass via incorrect Subject DN matching

Quick fix

GHSA-3f24-pcvm-5jqc — github.com/nats-io/nats-server/v2: upgrade to the fixed version with the command below.

go get github.com/nats-io/nats-server/v2@v2.11.15

Details

### Background

NATS.io is a high performance open source pub-sub distributed communication technology, built for the cloud, on-premise, IoT, and edge computing.

One authentication model supported is mTLS, deriving the NATS client identity from properties of the TLS Client Certificate.

### Problem Description

When using mTLS for client identity, with `verify_and_map` to derive a NATS identity from the client certificate's Subject DN, certain patterns of RDN would not be correctly enforced, allowing for authentication bypass.

This does require a valid certificate from a CA already trusted for client certificates, and `DN` naming patterns which the NATS maintainers consider highly unlikely.

So this is an unlikely attack. Nonetheless, administrators who have been very sophisticated in their `DN` construction patterns might conceivably be impacted.

### Affected Versions

Fixed in nats-server 2.12.6 & 2.11.15

### Workarounds

Developers should review their CA issuing practices.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/nats-io/nats-server/v2
Introduced in: 0Fixed in: 2.11.15
Fixgo get github.com/nats-io/nats-server/v2@v2.11.15
Go/github.com/nats-io/nats-server/v2
Introduced in: 2.12.0-RC.1Fixed in: 2.12.6
Fixgo get github.com/nats-io/nats-server/v2@v2.12.6
Go/github.com/nats-io/nats-server
Introduced in: 0

No fixed version published yet for github.com/nats-io/nats-server (go modules). Pin to a known-safe version or switch to an alternative.

References