RULE(RULE ID:333635)

Rule General Information
Release Date: 2021-06-03
Rule Name: Alibaba Canal Config Cloud Key Disclosure Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Since /api/v1/canal/config has not been authenticated and can be accessed directly, a series of sensitive information such as account password, accessKey, secretKey, etc. are leaked
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.