Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 39: FEDORA-2023-7d80ef0516 Urgent: NATS Authentication Vulnerability

fedora
Calendar Grey November 3, 2023
Dist Fedora Esm H88
The latest release of golang-github-nats-io-jwt-2 resolves critical vulnerabilities associated with account management and enhances overall security measures.
Contains updates to address CVE-2022-{28357,41717} and also NATS: 2023-01 nats- server: Adding accounts for just the system account adds auth bypass

Summary

JWT tokens signed using NKeys for Ed25519 for the NATS ecosystem.

Update Information:

Contains updates to address CVE-2022-{28357,41717} and also NATS: 2023-01 nats- server: Adding accounts for just the system account adds auth bypass

Change Log

* Wed Sep 20 2023 Mark E. Fuller - 2.5.2-1 - update to v2.5.2, close rhbz#2239736 * Wed Sep 13 2023 Mark E. Fuller - 2.5.0-1 - inital import, close rhbz#2237326

References

Fedora Update Notification FEDORA-2023-6b89bc0305 2023-11-03 18:20:20.950604 Name : golang-github-nats-io-jwt-2 Product : Fedora 39 Version : 2.5.2 Release : 1.fc39 URL : https://github.com/nats-io/jwt Summary : JWT tokens signed using NKeys for Ed25519 for the NATS ecosystem Description : JWT tokens signed using NKeys for Ed25519 for the NATS ecosystem.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6b89bc0305' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
important
Lowest
Low
Medium
High
Critical

Name: golang-github-nats-io-jwt-2
Product: Fedora 39
Version: 2.5.2
Release: 1.fc39
Summary: JWT tokens signed using NKeys for Ed25519 for the NATS ecosystem

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here