CVE Vulnerabilities

CVE-2021-3127

Improper Handling of Exceptional Conditions

Published: Mar 16, 2021 | Modified: Jul 12, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Jwt_library Nats * 2.0.1 (excluding)
Nats_server Nats 2.0.0 (including) 2.2.0 (excluding)
Golang-github-nats-io-jwt Ubuntu groovy *
Golang-github-nats-io-jwt Ubuntu hirsute *
Golang-github-nats-io-jwt Ubuntu impish *
Golang-github-nats-io-jwt Ubuntu kinetic *
Golang-github-nats-io-jwt Ubuntu lunar *
Golang-github-nats-io-jwt Ubuntu mantic *
Golang-github-nats-io-jwt Ubuntu trusty *

References