Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

nacos2.0.4漏洞问题 #6996

Closed
15098731779 opened this issue Jul 31, 2024 · 1 comment
Closed

nacos2.0.4漏洞问题 #6996

15098731779 opened this issue Jul 31, 2024 · 1 comment

Comments

@15098731779
Copy link

版本号:

最新版 jeecgboot

问题描述:

Nacos 是阿里巴巴推出来的一个开源项目,这是一个更易于构建云原生应用的动态服务发现、配置管理和服务管理平台。当配置为使用认证时(-Dnacos.core.auth.enabled=true),Nacos使用AuthFilter servlet过滤器来执行认证。这个过滤器有一个后门,使Nacos服务器可以绕过这个过滤器,从而跳过认证检查。这种机制依赖于用户代理的HTTP头,所以它很容易被欺骗。

是否可以升级nacos

错误截图:

友情提示:

  • 未按格式要求发帖、描述过于简单的,会被直接删掉;
  • 描述问题请图文并茂,方便我们理解并快速定位问题;
  • 如果使用的不是master,请说明你使用的分支;
@zhangdaiscott
Copy link
Member

可以参考最新代码,单独升级nacos就行

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants