漏洞描述
This template only works on Nuclei engine prior to version 2.3.3 and version >= 2.3.5. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce authentication. This filter has a backdoor that enables Nacos servers to bypass this filter and therefore skip authentication checks. This mechanism relies on the user-agent HTTP header so it can be easily spoofed. This issue may allow any user to carry out any administrative tasks on the Nacos server.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
securitylab.github.comhttps://securitylab.github.com/advisories/GHSL-2020-325_326-nacos/↗github.comhttps://github.com/alibaba/nacos/issues/4701↗github.comhttps://github.com/advisories/GHSA-36hp-jr8h-556f↗github.comhttps://github.com/alibaba/nacos/pull/4703↗github.comhttps://github.com/bakery312/Vulhub-Reproduce↗