CVE-2021-3127
HIGHCVSS 7.5/10EPSS 1.46%
Last modified
CVE-2021-3127 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.. EPSS estimates a 1.46% chance of exploitation in the next 30 days.
Description
NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linuxfoundation | Nats-Server | >= 2.0.0, < 2.2.0 |
| Nats | Jwt Library | < 2.0.1 |
References
- https://advisories.nats.io/CVE/CVE-2021-3127.txtExploit, Vendor Advisory
- https://advisories.nats.io/CVE/CVE-2021-3127.txtExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-3127?
NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.
How severe is CVE-2021-3127?
CVE-2021-3127 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.46% probability of exploitation in the next 30 days.
How do I fix CVE-2021-3127?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-31257The HintFile function in GPAC 1.0.1 allows attackers to caus…5.5
- CVE-2021-31258The gf_isom_set_extraction_slc function in GPAC 1.0.1 allows…5.5
- CVE-2021-31259The gf_isom_cenc_get_default_info_internal function in GPAC …5.5
- CVE-2021-31260The MergeTrack function in GPAC 1.0.1 allows attackers to ca…5.5
- CVE-2021-31261The gf_hinter_track_new function in GPAC 1.0.1 allows attack…5.5
- CVE-2021-31262The AV1_DuplicateConfig function in GPAC 1.0.1 allows attack…5.5
- CVE-2021-31272SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb…9.8
- CVE-2021-31274In LibreNMS < 21.3.0, a stored XSS vulnerability was identif…5.4
- CVE-2021-3128In ASUS RT-AX3000, ZenWiFi AX (XT8), RT-AX88U, and other ASU…7.5
- CVE-2021-31280An issue was discovered in tp5cms through 2017-05-25. admin.…6.1
- CVE-2021-3129Ignition before 2.5.2, as used in Laravel and other products…9.8
- CVE-2021-31291Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2021-3127?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
