CVE-2023-46129 is a cryptographic vulnerability affecting the NATS.io nkeys library (versions 0.4.0-0.4.5) and NATS server (versions 2.10.0-2.10.3). This flaw causes encryption, particularly in authentication callouts, to occur with an all-zeros key, resulting in a high confidentiality impact (CVSS 7.5) from an unauthenticated network attacker with low complexity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion regarding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.10.0, < 2.10.4CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:nats-server:*:*:*:*:*:*:*:* | ||
>= 0.4.0, < 0.4.6CPE matchmatch criteria | cpe:2.3:a:nats:nkeys:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-46129
Jun 11, 2024xkeys seal encryption used fixed key for all encryption
Oct 31, 2023nkeys: xkeys Seal encryption used fixed key for all encryption
Oct 29, 2023xkeys Seal encryption used fixed key for all encryption
Oct 10, 2023