Nacos 1.4.0 with authentication enabled, vulnerable to CVE-2021-29441: requests whose User-Agent is Nacos-Server skip the auth filter, so an unauthenticated user calls the user API and adds an account.
Not startedDockercommit 3736f9dx86_64 · aarch64Secret
Exploit CVE-2021-29441 to bypass Nacos authentication and read the flag.
The brief for this lab lives in its repository.