HIGH8.8
GHSA-2g86-r6w2-wqqr
Use of Hard-coded Credentials in Nacos
Details
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/com.alibaba.nacos:nacos-client
Introduced in:
0No fixed version published yet for com.alibaba.nacos:nacos-client (maven). Pin to a known-safe version or switch to an alternative.