[MAVEN:GHSA-2G86-R6W2-WQQR] Use of Hard-coded Credentials in Nacos

Severity High
Affected Packages 1
CVEs 1

An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.

Package Affected Version
pkg:maven/com.alibaba.nacos/nacos-client <= 2.0.3
ID
MAVEN:GHSA-2G86-R6W2-WQQR
Severity
high
URL
https://github.com/advisories/GHSA-2g86-r6w2-wqqr
Published
2022-07-06T00:00:30
(2 years ago)
Modified
2023-04-04T21:46:40
(17 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.alibaba.nacos/nacos-client com.alibaba.nacos nacos-client <= 2.0.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...