Important Nacos vulnerabilities
Remediation guide for important Nacos vulnerabilities
Threat Description
Nacos provides features for dynamic service discovery, service configuration, service metadata, and traffic management. Improper configurations or authorization can allow attackers to gain unauthorized access to Nacos or use malicious requests, which can lead to sensitive information leakage.
Vulnerability details: https://avd.aliyun.com/detail/AVD-2024-1738079?spm=5176.2020520154.sas.12.226eTkMRTkMRJu&lang=zh
Remediation suggestions
1. For information about how to troubleshoot and fix common security issues, see the official Nacos document, Nacos Secure Usage Best Practices - Access Control Practices.
Security issue | Remediation suggestion |
JSON Web Token (JWT) signature forgery with the default key | 1. Check whether the `token.secret.key` is set to the default value: `SecretKey01234567890123456789012345678901234567890123456789012345678`. If it is, update it to a custom Base64 string immediately. Ensure that this configuration value or environment variable is consistent across all Nacos nodes.
|
Unauthorized API access or permission bypass | 1. Follow the remediation suggestion for "JSON Web Token (JWT) signature forgery with the default key" to check and update the `token.secret.key`. 2. Check whether `server.identity` is set to the default values `serverIdentity` and `security`. If it is, update it to a custom Base64 string immediately. Ensure that this configuration value or environment variable is consistent across all Nacos nodes.
3. After you confirm that `token.secret.key` and `server.identity` are not set to their default values, check whether authentication is disabled. If authentication is disabled, enable it immediately.
|
SQL injection or actuator endpoint information leakage | Upgrade to the latest version to prevent this type of threat. |
2. Handle potentially leaked keys. If you stored keys, such as an Alibaba Cloud AccessKey, in plaintext in the Nacos service, rotate and disable the related AccessKey immediately. For more information, see Solutions for leaked AccessKeys.
If you encounter any difficulties during the remediation process or have other questions, go to Security Center, click Need Security Help, and contact a technical engineer for support.