CVE-2021-29441 is a critical authentication bypass vulnerability affecting Alibaba Nacos versions prior to 1.4.1. This flaw allows unauthenticated attackers to bypass security checks by spoofing the user-agent HTTP header, enabling them to perform administrative tasks on the Nacos server. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, the vulnerability poses a significant risk. While not on the KEV catalog or Hot List, public Nuclei templates exist for exploitation, though there is no evidence of active exploitation or widespread community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.1CPE matchmatch criteria | cpe:2.3:a:alibaba:nacos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.