NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| nats(npm) | 2.0.0-201 | 2.0.0-209 | N/A |
| nats.ws(npm) | 1.0.0-85 | 1.0.0-111 | N/A |
CVSS Metrics