S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-29442 Scanner

Detects 'Authentication Bypass' vulnerability in nacos affects v. before 1.4.1.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-29442
8.6
CVSShigh
Exploitable remotely over the internet · no authentication required.

Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While the /data/remove endpoint is properly protected with the @Secured annotation, the /derby endpoint is not protected and can be openly accessed by unauthenticated users. These endpoints are only valid when using embedded storage (derby DB) so this issue should not affect those installations using external storage (e.g. mysql)

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
nacosby alibaba
< 1.4.1
Updated Aug 19, 2026View on NVD →
Detail

Nacos is a popular platform designed to provide companies with dynamic service discovery and configuration, as well as service management. It simplifies the deployment and management of microservices and other distributed systems by allowing developers to configure, manage, and deploy services faster and more efficiently.

Recently, a vulnerability was discovered in Nacos versions before 1.4.1, known as CVE-2021-29442. This vulnerability allowed unauthenticated users to perform unauthorized operations on the ConfigOpsController API. Specifically, the "/derby" endpoint was left unprotected, and could be accessed by anyone with access to the Nacos platform.

If this vulnerability is exploited by cybercriminals, it can lead to a range of negative consequences. Unauthorized access to the application's data could occur if a malicious user were to wipe out the database or perform other risky operations on the system. Such an attack could result in significant financial loss and harm the company's reputation.

s4e.io's Pro Features can assist in identifying potential vulnerabilities in digital assets such as Nacos. These features allow users to quickly gain insights into potential attack vectors and correlative risks, empowering them to take proactive steps in securing their digital environments. Being proactive in guarding against cyber threats is crucial, as it has the potential to prevent damage before it occurs.

 

REFERENCES

Solution Advice

To prevent this from happening, the following precautions can be taken:

  • Upgrade to the latest version of Nacos (1.4.1 or newer).
  • Enforce the use of strong, unique passwords for all users.
  • Implement firewalls and access controls to restrict unauthorized access to Nacos.
  • Conduct regular security audits and penetration testing to spot any vulnerabilities before they can be exploited.
  • Monitor system logs in near real-time to detect any suspicious activity or unusual behavior.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.