{"id":"GHSA-vpjc-4jcv-jc29","summary":"NATS nats-server allows directory traversal via unintended path to a management action ","details":"NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.","aliases":["CVE-2022-28357","GO-2023-2066"],"modified":"2024-08-21T14:57:42.770075Z","published":"2023-09-19T03:30:34Z","database_specific":{"cwe_ids":["CWE-22"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-09-21T17:09:04Z","nvd_published_at":"2023-09-19T02:15:54Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-28357"},{"type":"WEB","url":"https://advisories.nats.io/CVE/CVE-2022-28357.txt"},{"type":"PACKAGE","url":"https://github.com/nats-io/nats-server"},{"type":"WEB","url":"https://github.com/nats-io/nats-server/releases/tag/v2.7.4"}],"affected":[{"package":{"name":"github.com/nats-io/nats-server","ecosystem":"Go","purl":"pkg:golang/github.com/nats-io/nats-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.2.0"},{"fixed":"2.7.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-vpjc-4jcv-jc29/GHSA-vpjc-4jcv-jc29.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}