Debian Golang-Github-Nats-Io-Jwt vulnerabilities
3 known vulnerabilities affecting debian/golang-github-nats-io-jwt.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2
Vulnerabilities
Page 1 of 1
CVE-2021-3127HIGHCVSS 7.5fixed in golang-github-nats-io-jwt 2.2.0-1 (bookworm)2021
CVE-2021-3127 [HIGH] CVE-2021-3127: golang-github-nats-io-jwt - NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access ...
NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.
Scope: local
bookworm: resolved (fixed in 2.2.0-1)
forky: resolved (fixed in 2.2.0-1)
sid: resolved (fixed in 2.2.0-1)
trixie: resolved (fixed in 2.2.0-1)
debian
CVE-2020-26892CRITICALCVSS 9.8fixed in golang-github-nats-io-jwt 2.2.0-1 (bookworm)2020
CVE-2020-26892 [CRITICAL] CVE-2020-26892: golang-github-nats-io-jwt - The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control be...
The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.
Scope: local
bookworm: resolved (fixed in 2.2.0-1)
forky: resolved (fixed in 2.2.0-1)
sid: resolved (fixed in 2.2.0-1)
trixie: resolved (fixed in 2.2.0-1)
debian
CVE-2020-26521HIGHCVSS 7.5fixed in golang-github-nats-io-jwt 2.2.0-1 (bookworm)2020
CVE-2020-26521 [HIGH] CVE-2020-26521: golang-github-nats-io-jwt - The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a n...
The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).
Scope: local
bookworm: resolved (fixed in 2.2.0-1)
forky: resolved (fixed in 2.2.0-1)
sid: resolved (fixed in 2.2.0-1)
trixie: resolved (fixed in 2.2.0-1)
debian