CVE-2021-3127

Related Vulnerabilities: CVE-2021-3127  

NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.

Description

The MITRE CVE dictionary describes this issue as:

NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.

Additional Information

  • Bugzilla 1944543: CVE-2021-3127 nats-server: mishandling Import Token bindings may lead to Incorrect Access Control
  • CWE-287: Improper Authentication
  • FAQ: Frequently asked questions about CVE-2021-3127