Description
Nacos is a platform designed for dynamic service discovery and configuration and service management.
Nacos before 1.4.1 has an authentication bypass vulnerability. An attacker can bypass the authentication with a specially crafted HTTP request and get full access to the system.
Remediation
Upgrade to the latest version of Nacos
References
Related Vulnerabilities
MySQL CVE-2017-10311 Vulnerability (CVE-2017-10311)
OpenSSL Improper Authentication Vulnerability (CVE-2023-2975)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3742)
OpenSSL NULL Pointer Dereference Vulnerability (CVE-2006-4343)
Oracle HTTP Server Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-40438)