com.alibaba.nacos:nacos-config@0.6.1 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the com.alibaba.nacos:nacos-config package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Improper Authentication

Affected versions of this package are vulnerable to Improper Authentication. When nacos is deployed in the default configuration, the administrator dashboard can be accessed without authentication. This can be leveraged to execute arbitrary SQL queries, which leads to the disclosure of sensitive information.

How to fix Improper Authentication?

A fix was pushed into the master branch but not yet published.

[0,)