CyberRota Analysis
AI-GeneratedNATS Server versions prior to 2.14.3 and 2.12.12 are vulnerable to an authentication bypass, allowing a client to register as the no_auth_user through a specific parser path when the initial operation is not a CONNECT. This vulnerability can lead to unauthorized access, circumventing user-level connection restrictions and potentially compromising the security of the messaging system. Organizations using affected versions should prioritize upgrading to the patched versions to mitigate the risk of unauthorized access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be registered as the configured no_auth_user through a parser path used when the first client operation was not CONNECT, bypassing user-level connection restrictions such as allowed_connection_types or proxy_required that normal authentication would apply. This issue is fixed in versions 2.14.3 and 2.12.12.
Related CVEs
Other vulnerabilities affecting the same vendor(s)