MEDIUM 6.1 Maven
Cross-site Scripting in Nacos
GHSA-4gr7-qw2q-jxh6 · CVE-2021-44667
Published · Modified
Description
A Cross Site Scripting (XSS) vulnerability exists in Nacos prior to 1.4.5 and 2.1.0-BETA in auth/users via the (1) pageSize and (2) pageNo parameters.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2021-44667
- WEB https://github.com/alibaba/nacos/issues/7359
- WEB https://github.com/alibaba/nacos/pull/7364
- WEB https://github.com/alibaba/nacos/pull/8980
- WEB https://github.com/alibaba/nacos/commit/cd6d7e33b94f24814701f3faf8b632e5e85444c5
- WEB https://github.com/alibaba/nacos/commit/d062fcafad0acd01673d404319526415a4af372b
- PACKAGE https://github.com/alibaba/nacos
Ready to move
Start Securing
Free, no credit card | First findings in minutes