Description
Preview versions of two NPM packages and one Deno package from the NATS project contain an information disclosure flaw, leaking options to the NATS server; for one package, this includes TLS private credentials.
Recommendation
Update the nats
package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.0.0-201, <= 2.0.0-206
- Patched version(s): 2.0.0-209
References
Related Issues
- Prototype Pollution in lodash (GHSA-jf85-cpcp-j695) 4 - CVE-2019-10744
- Prototype Pollution in lodash (GHSA-jf85-cpcp-j695) 2 - CVE-2019-10744
- Passbolt Browser Extension leaks password information - CVE-2024-33669
- JSONata expression can pollute the "Object" prototype - CVE-2024-27307
- Tags:
- npm
- nats
Anything's wrong? Let us know Last updated on September 11, 2023