CVE-2020-26149

NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:nats.deno:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:nats.js:*:*:*:*:*:node.js:*:*
cpe:2.3:a:linuxfoundation:nats.ws:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:19

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2020/09/30/3 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2020/09/30/3 - Mailing List, Third Party Advisory
References () https://github.com/nats-io/nats.deno/compare/v1.0.0-8...v1.0.0-9 - Patch, Third Party Advisory () https://github.com/nats-io/nats.deno/compare/v1.0.0-8...v1.0.0-9 - Patch, Third Party Advisory
References () https://github.com/nats-io/nats.ws/commit/0a37ac2a411ff63f0707cda69a268c5fc4079eb7 - Patch, Third Party Advisory () https://github.com/nats-io/nats.ws/commit/0a37ac2a411ff63f0707cda69a268c5fc4079eb7 - Patch, Third Party Advisory

Information

Published : 2020-09-30 18:15

Updated : 2024-11-21 05:19


NVD link : CVE-2020-26149

Mitre link : CVE-2020-26149

CVE.ORG link : CVE-2020-26149


JSON object : View

Products Affected

linuxfoundation

  • nats.deno
  • nats.js
  • nats.ws
CWE
CWE-522

Insufficiently Protected Credentials