CVE-2020-26149

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
30/09/2020
Last modified:
09/10/2020

Description

NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:linuxfoundation:nats.deno:*:*:*:*:*:*:*:* 1.0.0-9 (excluding)
cpe:2.3:a:linuxfoundation:nats.js:*:*:*:*:*:node.js:*:* 2.0.0-209 (excluding)
cpe:2.3:a:linuxfoundation:nats.ws:*:*:*:*:*:*:*:* 1.0.0-111 (excluding)