CVE-2021-29441

Authentication Bypass by Spoofing in maven/com.alibaba.nacos/nacos-api

Identifiers

CVE-2021-29441, GHSA-36hp-jr8h-556f

Package Slug

maven/com.alibaba.nacos/nacos-api

Vulnerability

Authentication Bypass by Spoofing

Description

Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos, when configured to use authentication -Dnacos.core.auth.enabled=true it uses the AuthFilter servlet filter to enforce authentication. This filter has a backdoor that enables Nacos servers to bypass this filter and therefore skip authentication checks. This mechanism relies on the user-agent HTTP header so it can be easily spoofed. This issue may allow any user to carry out any administrative tasks on the Nacos server.

Affected Versions

All versions before 1.4.1

Solution

Upgrade to version 1.4.1 or above.

Last Modified

2021-05-10

source