Description
Nacos is a platform designed for dynamic service discovery and configuration and service management.
Nacos before 1.4.1 has an authentication bypass vulnerability. An attacker can bypass the authentication with a specially crafted HTTP request and get full access to the system.
Remediation
Upgrade to the latest version of Nacos
References
Related Vulnerabilities
MySQL CVE-2024-21050 Vulnerability (CVE-2024-21050)
Jenkins CVE-2023-44487 Vulnerability (CVE-2023-44487)
b2evolution Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-7352)
Django Improper Validation of Specified Quantity in Input Vulnerability (CVE-2024-41991)
PHP Integer Overflow or Wraparound Vulnerability (CVE-2022-37454)