CVE-2021-43116 Information

Description

An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password click on login to capture packets and then change the returned package which lets a malicious user login.

Reference

https://github.com/alibaba/nacos/issues/7182 https://github.com/alibaba/nacos/issues/7127

Share on: