QID 981831

QID 981831: Java (maven) Security Update for com.alibaba.nacos:nacos-common (GHSA-qf76-pr7x-h7r4)

Nacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details interface. Then other Nacos service names can be accessed through the service list interface. Service details can then be accessed when not logged in. (detail:https://github.com/alibaba/nacos/issues/2284)

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-qf76-pr7x-h7r4 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981831

    Software Advisories
    Advisory ID Software Component Link
    GHSA-qf76-pr7x-h7r4 com.alibaba.nacos:nacos-common URL Logo github.com/advisories/GHSA-qf76-pr7x-h7r4