High severity8.8NVD Advisory· Published Jul 5, 2022· Updated Jun 17, 2026
CVE-2021-43116
CVE-2021-43116
Description
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on login to capture packets and then change the returned package, which lets a malicious user login.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.alibaba.nacos:nacos-clientMaven | <= 2.0.3 | — |
Affected products
3- Nacos/Nacosdescription
Patches
Vulnerability mechanics
References
5- github.com/alibaba/nacos/issues/7127nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/alibaba/nacos/issues/7182nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-2g86-r6w2-wqqrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-43116ghsaADVISORY
- packetstormsecurity.com/files/171638/Nacos-2.0.3-Access-Control.htmlnvdWEB
News mentions
0No linked articles in our index yet.