NATS: 2023-02: nkeys: xkeys Seal encryption used fixed key for all encryption

NATS: 2023-02: nkeys: xkeys Seal encryption used fixed key for all encryption

Open Source Security 

Posted by Byron Ruth on Oct 31

NATS-advisory-ID: 2023-02
Aliases: CVE-2023-46129, GHSA-mr45-rx8q-wcm9
Date: 2023-10-26
Fixed-In: nkeys 0.4.6; nats-server 2.10.4

Background:

NATS.io is a high performance open source pub-sub distributed communication
technology, built for the cloud, on-premise, IoT, and edge computing.

The cryptographic key handling library, nkeys, recently gained support
for encryption, not just for signing/authentication. This is used
in nats-server 2.10…
 Read More 

Schreibe einen Kommentar

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert