PT-2022-11790 · Nacos · Nacos

Published

2022-07-05

·

Updated

2023-04-03

·

CVE-2021-43116

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nacos version 2.0.3
Description An Access Control issue exists in the access prompt page. A malicious user can login by capturing packets, entering username and password, clicking on login, and then changing the returned package.
Recommendations For Nacos version 2.0.3, consider temporarily restricting access to the login functionality until a patch is available. As a workaround, monitor network traffic for suspicious packet modifications to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43116
GHSA-2G86-R6W2-WQQR

Affected Products

Nacos