« Volver al listado

CVE-2025-30215

Estado: AplazadaCrítica (9.6)—

NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting from 2.2.0 but prior to 2.10.27 and 2.11.1, the management of JetStream assets happens with messages in the $JS. subject namespace in the system account; this is partially exposed into regular accounts to allow account holders to manage their assets. Some of the JS API requests were missing access controls, allowing any user with JS management permissions in any account to perform certain administrative actions on any JS asset in any other account. At least one of the unprotected APIs allows for data destruction. None of the affected APIs allow disclosing stream contents. This vulnerability is fixed in v2.11.1 or v2.10.27.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad en NATS-Server que requiere autenticación previa (PR:L) y acceso en red sin UI, permitiendo escalada lateral entre cuentas para destruir datos JetStream. Explotación remota (T1210), acceso elevado entre cuentas (T1078.002) y manipulación de datos (T1565.001).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-30215",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-30215",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-17T14:22:25.239466Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9.6,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 3.1
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "nats-io",
          "product": "nats-server",
          "versions": [
            {
              "status": "affected",
              "version": ">= 2.2.0, < 2.10.27"
            },
            {
              "status": "affected",
              "version": ">= 2.11.0-RC.1, < 2.11.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-04-16T00:15:19.767",
  "references": [
    {
      "url": "https://advisories.nats.io/CVE/secnote-2025-01.txt",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/nats-io/nats-server/security/advisories/GHSA-fhg8-qxh5-7q3w",
      "source": "security-advisories@github.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2025/04/08/5",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/nats-io/nats-server/security/advisories/GHSA-fhg8-qxh5-7q3w",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        },
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting from 2.2.0 but prior to 2.10.27 and 2.11.1, the management of JetStream assets happens with messages in the $JS. subject namespace in the system account; this is partially exposed into regular accounts to allow account holders to manage their assets. Some of the JS API requests were missing access controls, allowing any user with JS management permissions in any account to perform certain administrative actions on any JS asset in any other account. At least one of the unprotected APIs allows for data destruction. None of the affected APIs allow disclosing stream contents. This vulnerability is fixed in v2.11.1 or v2.10.27."
    },
    {
      "lang": "es",
      "value": "NATS-Server es un servidor de alto rendimiento para NATS.io, el sistema de mensajería nativo en la nube y el edge. En versiones a partir de la 2.2.0, pero anteriores a las 2.10.27 y 2.11.1, la gestión de los recursos de JetStream se realiza mediante mensajes en el espacio de nombres de sujeto $JS. de la cuenta del sistema; este espacio está parcialmente expuesto en las cuentas normales para que los titulares de las cuentas puedan gestionar sus recursos. Algunas solicitudes a la API de JS carecían de controles de acceso, lo que permitía a cualquier usuario con permisos de gestión de JS en cualquier cuenta realizar ciertas acciones administrativas en cualquier recurso de JS de cualquier otra cuenta. Al menos una de las API sin protección permite la destrucción de datos. Ninguna de las API afectadas permite divulgar el contenido de los flujos de datos. Esta vulnerabilidad se ha corregido en las versiones 2.11.1 o 2.10.27."
    }
  ],
  "lastModified": "2026-06-17T09:08:22.323",
  "sourceIdentifier": "security-advisories@github.com"
}