packetstormsecurity.com
http://packetstormsecurity.com/files/171638/Nacos-2.0.3-Access-Control.html CVE-2021-43116
HIGH
Use of Hard-coded Credentials in Nacos
Record summary
CVE-2021-43116 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
com.alibaba.nacos:nacos-clientBrowse Maven / com.alibaba.nacos:nacos-client | GitHub Advisory | Through 2.0.3 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBNacos 2.0.3 - Access Control vulnerabilityExploitDB exploitby Jenson ZhaoNot analyzed1 file
References
5github.com
https://github.com/alibaba/nacos github.com
https://github.com/alibaba/nacos/issues/7127 github.com
https://github.com/alibaba/nacos/issues/7182 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-43116