Description
Nacos is a platform designed for dynamic service discovery and configuration and service management.
Nacos before 1.4.1 has an authentication bypass vulnerability. An attacker can bypass the authentication with a specially crafted HTTP request and get full access to the system.
Remediation
Upgrade to the latest version of Nacos
References
Related Vulnerabilities
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-0218)
WordPress Ultimate Member Plugin Improper Privilege Management Vulnerability (CVE-2020-36156)
MediaWiki CVE-2021-45471 Vulnerability (CVE-2021-45471)
Joomla Permissions, Privileges, and Access Controls Vulnerability (CVE-2006-4475)