Skip to content

The nats-server v2.1.2 is used by kit , I noticed nats-server v2.1.2 has a High-Risk Vulnerability CVE-2022-24450, However is kit affetcd by this CVE ? #1223

Answered by ChrisHines
liufangwai asked this question in Q&A
Discussion options

You must be logged in to vote

No. The most recent release of go-kit (v0.12.0) uses nats-server v2.5.0 and only for tests. The non-test code in go-kit does not use nats-server at all, only the nats client.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@liufangwai
Comment options

Answer selected by peterbourgon
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants