CVE-2021-29441, GHSA-36hp-jr8h-556f
maven/com.alibaba.nacos/nacos-api
Authentication Bypass by Spoofing
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos, when configured to use authentication -Dnacos.core.auth.enabled=true
it uses the AuthFilter
servlet filter to enforce authentication. This filter has a backdoor that enables Nacos servers to bypass this filter and therefore skip authentication checks. This mechanism relies on the user-agent HTTP header so it can be easily spoofed. This issue may allow any user to carry out any administrative tasks on the Nacos server.
All versions before 1.4.1
Upgrade to version 1.4.1 or above.
2021-05-10
source |