Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Nats-Server 路径遍历漏洞
Vulnerability Description
Nats-Server是一个用于 Nats.io、云和边缘本机消息传递系统的高性能服务器。 Nats-Server 2.7.4 之前版本的 JetStream 组件存在安全漏洞,该漏洞源于没有正确清理存档文件的元素。NATS 的用户可能导致 NATS 服务器将任意内容写入攻击者控制的文件名。
CVSS Information
N/A
Vulnerability Type
N/A