Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 39: FEDORA-2023-6b89bc0305 Critical Auth Bypass Issue

fedora
Calendar Grey November 3, 2023
Dist Fedora Esm H88
Enhancements in Fedora 39 tackle significant challenges in the golang client for NATS, fixing vulnerabilities related to authentication bypass.
Contains updates to address CVE-2022-{28357,41717} and also NATS: 2023-01 nats- server: Adding accounts for just the system account adds auth bypass

Summary

Golang client for NATS, the cloud native messaging system.

Update Information:

Contains updates to address CVE-2022-{28357,41717} and also NATS: 2023-01 nats- server: Adding accounts for just the system account adds auth bypass

Change Log

* Tue Sep 26 2023 Mark E. Fuller - 1.30.1-1 - update to v1.30.1, close rhbz#2240140 * Fri Sep 22 2023 Mark E. Fuller - 1.30.0-2 - update to v1.30.0, close rhbz#2240140 * Fri Sep 22 2023 Mark E. Fuller - 1.30.0-1 - bootstrap v1.30.0 * Tue Sep 19 2023 Mark E. Fuller - 1.29.0-5 - rebuild without bootstrap * Tue Sep 19 2023 Mark E. Fuller - 1.29.0-4 - disable tests for bootstrap * Fri Sep 15 2023 Mark E. Fuller - 1.29.0-3 - bump to v1.29.0, close rhbz#1956588; fix requirement (forgot to add spec) * Fri Sep 15 2023 Mark E. Fuller - 1.29.0-2 - bump to v1.29.0, close rhbz#1956588; fix requirement

References

Fedora Update Notification FEDORA-2023-6b89bc0305 2023-11-03 18:20:20.950604 Name : golang-github-nats-io Product : Fedora 39 Version : 1.30.1 Release : 1.fc39 URL : https://github.com/nats-io/nats.go Summary : Golang client for NATS, the cloud native messaging system Description : Golang client for NATS, the cloud native messaging system.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6b89bc0305' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: golang-github-nats-io
Product: Fedora 39
Version: 1.30.1
Release: 1.fc39
Summary: Golang client for NATS, the cloud native messaging system

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here