NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings are mishandled.
| Software | From | Fixed in |
|---|---|---|
| nats / jwt_library | - | 2.0.1 |
| nats / nats_server | 2.0.0 | 2.2.0 |
github.com/nats-io/jwt
|
2.0.0 | 2.0.1 |
github.com/nats-io/nats-server/v2/server
|
- | 2.2.0 |