PT-2022-11790 · Nacos · Nacos
Published
2022-07-05
·
Updated
2023-04-03
·
CVE-2021-43116
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nacos version 2.0.3
Description
An Access Control issue exists in the access prompt page. A malicious user can login by capturing packets, entering
username and password, clicking on login, and then changing the returned package.Recommendations
For Nacos version 2.0.3, consider temporarily restricting access to the login functionality until a patch is available. As a workaround, monitor network traffic for suspicious packet modifications to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nacos