Vulnerabilities > Linuxfoundation > Nats Server > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-09-19 CVE-2022-28357 Path Traversal vulnerability in Linuxfoundation Nats-Server
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
network
low complexity
linuxfoundation CWE-22
critical
9.8
2020-11-06 CVE-2020-26892 Use of Hard-coded Credentials vulnerability in multiple products
The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.
network
low complexity
linuxfoundation fedoraproject CWE-798
critical
9.8