Alpine: nats-server: security update to 2.10.27-r0

critical Tenable Self-Hosted Container Security Plugin ID 426048

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In
versions starting from 2.2.0 but prior to 2.10.27 and 2.11.1, the management of JetStream assets happens
with messages in the $JS. subject namespace in the system account; this is partially exposed into regular
accounts to allow account holders to manage their assets. Some of the JS API requests were missing access
controls, allowing any user with JS management permissions in any account to perform certain
administrative actions on any JS asset in any other account. At least one of the unprotected APIs allows
for data destruction. None of the affected APIs allow disclosing stream contents. This vulnerability is
fixed in v2.11.1 or v2.10.27. (CVE-2025-30215)

See Also

https://security.alpinelinux.org/vuln/CVE-2025-30215

Plugin Details

Severity: Critical

ID: 426048

Version: Revision 1.9

Type: Local

Published: 5/16/2025

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.8

Percentile: 97.03

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:C

CVSS Score Source: CVE-2025-30215

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/8/2025

Reference Information

CVE: CVE-2025-30215