Vulnerability Details CVE-2023-47090
NATS nats-server before 2.9.23 and 2.10.x before 2.10.2 has an authentication bypass. An implicit $G user in an authorization block can sometimes be used for unauthenticated access, even when the intention of the configuration was for each user to have an account. The earliest affected version is 2.2.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 47.0%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2023-47090
-
cpe:2.3:a:linuxfoundation:nats-server:2.10.0
-
cpe:2.3:a:linuxfoundation:nats-server:2.10.1
-
cpe:2.3:a:linuxfoundation:nats-server:2.2.0
-
cpe:2.3:a:linuxfoundation:nats-server:2.2.1
-
cpe:2.3:a:linuxfoundation:nats-server:2.2.2
-
cpe:2.3:a:linuxfoundation:nats-server:2.2.3
-
cpe:2.3:a:linuxfoundation:nats-server:2.2.4
-
cpe:2.3:a:linuxfoundation:nats-server:2.2.5
-
cpe:2.3:a:linuxfoundation:nats-server:2.2.6
-
cpe:2.3:a:linuxfoundation:nats-server:2.3.0
-
cpe:2.3:a:linuxfoundation:nats-server:2.3.1
-
cpe:2.3:a:linuxfoundation:nats-server:2.3.2
-
cpe:2.3:a:linuxfoundation:nats-server:2.3.3
-
cpe:2.3:a:linuxfoundation:nats-server:2.3.4
-
cpe:2.3:a:linuxfoundation:nats-server:2.4.0
-
cpe:2.3:a:linuxfoundation:nats-server:2.5.0
-
cpe:2.3:a:linuxfoundation:nats-server:2.6.0
-
cpe:2.3:a:linuxfoundation:nats-server:2.6.1
-
cpe:2.3:a:linuxfoundation:nats-server:2.6.2
-
cpe:2.3:a:linuxfoundation:nats-server:2.6.3
-
cpe:2.3:a:linuxfoundation:nats-server:2.6.4
-
cpe:2.3:a:linuxfoundation:nats-server:2.6.5
-
cpe:2.3:a:linuxfoundation:nats-server:2.6.6
-
cpe:2.3:a:linuxfoundation:nats-server:2.7.0
-
cpe:2.3:a:linuxfoundation:nats-server:2.7.1
-
cpe:2.3:a:linuxfoundation:nats-server:2.7.2
-
cpe:2.3:a:linuxfoundation:nats-server:2.7.3
-
cpe:2.3:a:linuxfoundation:nats-server:2.7.4
-
cpe:2.3:a:linuxfoundation:nats-server:2.8.0
-
cpe:2.3:a:linuxfoundation:nats-server:2.8.1
-
cpe:2.3:a:linuxfoundation:nats-server:2.8.2
-
cpe:2.3:a:linuxfoundation:nats-server:2.8.3
-
cpe:2.3:a:linuxfoundation:nats-server:2.8.4
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.0
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.1
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.10
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.11
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.12
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.14
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.15
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.16
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.17
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.18
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.19
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.2
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.20
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.21
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.22
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.3
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.4
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.5
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.6
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.7
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.8
-
cpe:2.3:a:linuxfoundation:nats-server:2.9.9