Record summary

CVE-2021-43116 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

1
ProductSourceVersion rangeStatus

com.alibaba.nacos:nacos-client

Browse Maven / com.alibaba.nacos:nacos-client
GitHub AdvisoryThrough 2.0.3affected

Proofs of concept

1

Catalogued exploits

ExploitDBNacos 2.0.3 - Access Control vulnerabilityExploitDB exploitby Jenson ZhaoNot analyzed1 file
ExploitDB

PoC details

References

5