Описание
Use of Hard-coded Credentials in Nacos
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.
Пакеты
Наименование
com.alibaba.nacos:nacos-client
maven
Затронутые версииВерсия исправления
<= 2.0.3
Отсутствует
Связанные уязвимости
CVSS3: 8.8
nvd
больше 3 лет назад
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.