CVE-2019-13126
Dashboard / Vulnerabilities / CVE-2019-13126
Summary:
Details: An integer overflow in NATS Server before 2.0.2 allows a remote attacker to crash the server by sending a crafted request. If authentication is enabled, then the remote attacker must have first authenticated.
References: https://github.com/nats-io/nats-server/pull/1053, https://www.twistlock.com/labs-blog/finding-dos-vulnerability-nats-go-fuzz-cve-2019-13126/
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
v2.0.0
v2.0.0-RC19
v2.0.0-RC14
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
