Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 39: FEDORA-2023-6b89bc0305 Moderate NATS Auth Bypass Issue

fedora
Calendar Grey November 3, 2023
Dist Fedora Esm H88
The latest Fedora update includes a fix for a critical NATS authentication loophole along with addressing CVE-2022 security flaws within the golang library.
Contains updates to address CVE-2022-{28357,41717} and also NATS: 2023-01 nats- server: Adding accounts for just the system account adds auth bypass

Summary

A public-key signature system based on Ed25519 for the NATS ecosystem.

Update Information:

Contains updates to address CVE-2022-{28357,41717} and also NATS: 2023-01 nats- server: Adding accounts for just the system account adds auth bypass

Change Log

* Wed Sep 20 2023 Mark E. Fuller - 0.4.5-2 - bump to v0.4.5, close rhbz#2239762, upload correct source * Wed Sep 20 2023 Mark E. Fuller - 0.4.5-1 - bump to v0.4.5, close rhbz#2239762

References

Fedora Update Notification FEDORA-2023-6b89bc0305 2023-11-03 18:20:20.950604 Name : golang-github-nats-io-nkeys Product : Fedora 39 Version : 0.4.5 Release : 2.fc39 URL : https://github.com/nats-io/nkeys Summary : Public-key signature system based on Ed25519 for the NATS ecosystem Description : A public-key signature system based on Ed25519 for the NATS ecosystem.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6b89bc0305' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Name: golang-github-nats-io-nkeys
Product: Fedora 39
Version: 0.4.5
Release: 2.fc39
Summary: Public-key signature system based on Ed25519 for the NATS ecosystem

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here