CVE-2021-29441: Nacos <1.4.1 - Authentication Bypass

CVE-2021-29441: Nacos <1.4.1 - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享
CVE-2021-29441: Nacos <1.4.1 - Authentication Bypass
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-29441: nacos <1.4.1 – Authentication Bypass

漏洞描述

This template only works on Nuclei engine prior to version 2.3.3 and version >= 2.3.5.

In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true)

Nacos uses the AuthFilter servlet filter to enforce authentication. This filter has a backdoor that

enables Nacos servers to bypass this filter and therefore skip authentication checks.

This mechanism relies on the user-agent HTTP header so it can be easily spoofed.

This issue may allow any user to carry out any administrative tasks on the Nacos server.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享