x/vulndb: potential Go vuln in github.com/nats-io/nats-server: CVE-2022-28357 #2066
Labels
excluded: EFFECTIVELY_PRIVATE
This vulnerability exists in a package can be imported, but isn't meant to be outside that module.
CVE-2022-28357 references github.com/nats-io/nats-server, which may be a Go module.
Description:
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
References:
Cross references:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: