CVE-2020-19676

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-19676
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-19676.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-19676
Aliases
Published
2020-09-30T18:15:23Z
Modified
2024-05-14T07:59:25.587545Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Nacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details interface. Then other Nacos service names can be accessed through the service list interface. Service details can then be accessed when not logged in. (detail:https://github.com/alibaba/nacos/issues/2284)

References

Affected packages

Git / github.com/alibaba/nacos

Affected ranges

Type
GIT
Repo
https://github.com/alibaba/nacos
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

0.*

0.2.1
0.2.1-RC1
0.3.0
0.3.0-RC1
0.4.0
0.5.0
0.6.0
0.6.1
0.7.0
0.8.0
0.8.0-SNAPSHOT
0.9.0

1.*

1.0.0
1.0.0-RC1
1.0.0-RC2
1.0.0-RC3
1.0.1
1.1.0
1.1.3
1.1.4

v0.*

v0.1.0
v0.2.0