CVE-2020-26149
Summary
| CVE | CVE-2020-26149 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-30 18:15:00 UTC |
| Updated | 2020-10-09 14:51:00 UTC |
| Description | NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [update] [security] updated nats-base-client to v1.0.0-9 (#47) · nats-io/nats.ws@0a37ac2 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| oss-security - [CVE-2020-26149] NATS project vulnerabilities: nats.js, (nats.ws,
nats.deno) |
CONFIRM |
www.openwall.com |
Mailing List, Third Party Advisory |
| Comparing v1.0.0-8...v1.0.0-9 · nats-io/nats.deno · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983508 Nodejs (npm) Security Update for nats.ws (GHSA-82rf-q3pr-4f6p)