CVE-2021-29442, GHSA-36hp-jr8h-556f
maven/com.alibaba.nacos/nacos-api
Missing Authentication for Critical Function
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos, the ConfigOpsController
lets the user perform management operations like querying the database or even wiping it out. While the /data/remove
endpoint is properly protected with the @Secured
annotation, the /derby
endpoint is not protected and can be openly accessed by unauthenticated users. These endpoints are only valid when using embedded storage (derby DB) so this issue should not affect those installations using external storage (e.g. mysql).
All versions before 1.4.1
Upgrade to version 1.4.1 or above.
2021-05-10
source |