Nacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details interface. Then other Nacos service names can be accessed through the service list interface. Service details can then be accessed when not logged in. (detail:https://github.com/alibaba/nacos/issues/2284)
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://github.com/alibaba/nacos/issues/2284 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-09-30T17:52:39
Updated: 2024-08-04T14:15:28.366Z
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-19676
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-09-30T18:15:23.663
Modified: 2024-11-21T05:09:19.070
Link: CVE-2020-19676
Redhat
No data.