Vulnerability record · CVE-2021-29442 · published 27 April 2021
CVE-2021-29442: Nacos ConfigOpsController derby endpoint missing authentication
Alibaba · Nacos
In Nacos before 1.4.1, the ConfigOpsController exposes a /derby endpoint that lacks the @Secured annotation applied to /data/remove, allowing unauthenticated access to management operations such as querying or wiping the embedded database. The issue only affects installations using embedded Derby storage, not those backed by external databases like MySQL.
Description
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While the /data/remove endpoint is properly protected with the @Secured annotation, the /derby endpoint is not protected and can be openly accessed by unauthenticated users. These endpoints are only valid when using embedded storage (derby DB) so this issue should not affect those installations using external storage (e.g. mysql)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 with no authentication required, public exploit references, and a very high EPSS percentile make this a high-priority exposure for affected embedded-storage deployments.
What it is
In Nacos before 1.4.1, the ConfigOpsController exposes a /derby endpoint that lacks the @Secured annotation applied to /data/remove, allowing unauthenticated access to management operations such as querying or wiping the embedded database. The issue only affects installations using embedded Derby storage, not those backed by external databases like MySQL.
Impact
An unauthenticated attacker can read data from the embedded Derby database and potentially destroy it, causing loss of configuration and service-discovery data. The CVSS vector rates confidentiality impact as high with no integrity or availability impact recorded.
Attack surface
Reachable over the network via HTTP against the Nacos ConfigOpsController /derby endpoint; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Only deployments using embedded Derby storage are exposed.
Exploitation
Not listed in CISA KEV, but EPSS probability is 0.6663 (99.25th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Nacos to version 1.4.1 or later, which contains the patch referenced in PR 4517.
- If immediate upgrade is not possible, restrict network access to the ConfigOpsController endpoints so only trusted administrative hosts can reach them.
- Migrate from embedded Derby storage to an external database such as MySQL, which the advisory states is not affected.
- Audit Nacos deployments for embedded Derby usage and confirm whether the /derby endpoint is externally reachable.
- Monitor for unauthorized access attempts to /derby and other ConfigOpsController paths.
Detection
- Search HTTP access logs for requests to the /derby endpoint on Nacos servers, especially from unexpected source IPs.
- Alert on unauthenticated requests to ConfigOpsController management paths.
- Monitor for unexpected database read or wipe activity in embedded Derby-backed Nacos instances.
- Inventory Nacos instances and flag any running versions below 1.4.1 with embedded storage.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/advisories/GHSA-36hp-jr8h-556f | ExploitThird Party Advisory |
| https://github.com/alibaba/nacos/issues/4463 | ExploitThird Party Advisory |
| https://github.com/alibaba/nacos/pull/4517 | PatchThird Party Advisory |
| https://github.com/advisories/GHSA-36hp-jr8h-556f | ExploitThird Party Advisory |
| https://github.com/alibaba/nacos/issues/4463 | ExploitThird Party Advisory |
| https://github.com/alibaba/nacos/pull/4517 | PatchThird Party Advisory |
Track CVE-2021-29442 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-29442), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.