CVE-2020-19676
Last modified
CVE-2020-19676 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Nacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details interface. EPSS estimates a 1.42% chance of exploitation in the next 30 days.
Description
Nacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details interface. Then other Nacos service names can be accessed through the service list interface. Service details can then be accessed when not logged in. (detail:https://github.com/alibaba/nacos/issues/2284)
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Alibaba | Nacos | 1.1.4 |
References
- https://github.com/alibaba/nacos/issues/2284Exploit, Issue Tracking, Third Party Advisory
- https://github.com/alibaba/nacos/issues/2284Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-19676?
How severe is CVE-2020-19676?
How do I fix CVE-2020-19676?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-19667Stack-based buffer overflow and unconditional jump in ReadXP…7.8
- CVE-2020-19668Unverified indexs into the array lead to out of bound access…6.5
- CVE-2020-19669Cross Site Request Forgery (CSRF) vulnerability exists in Ey…8.8
- CVE-2020-1967Server or client applications that call the SSL_check_chain(…7.5
- CVE-2020-19670In Niushop B2B2C Multi-Business Basic Edition V1.11, authent…4.9
- CVE-2020-19672Niushop B2B2C Multi-business basic version V1.11, can bypass…9.8
- CVE-2020-19678Directory Traversal vulnerability found in Pfsense v.2.1.3 a…7.5
- CVE-2020-1968The Raccoon attack exploits a flaw in the TLS specification …3.7
- CVE-2020-19682A Cross Site Request Forgery (CSRF) vulnerability exits in Z…8.8
- CVE-2020-19683A Cross Site Scripting (XSS) exists in ZZZCMS V1.7.1 via an …5.4
- CVE-2020-1969Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-19692Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 al…9.8
Are you affected by CVE-2020-19676?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
