Alibaba
11 known vulnerabilities
Top Products
The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow
An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on l
The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the defa
A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo param
In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal.
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before ver
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before ver
Nacos 1.1.4 is affected by: Incorrect Access Control. An environment can be set up locally to get the service details in
parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attac
Frequently Asked Questions
How many CVEs affect Alibaba?
Alibaba has 11 CVE records in our database, including 1 critical and 6 high severity vulnerabilities.
What are the most severe Alibaba vulnerabilities?
Alibaba has 1 critical severity (CVSS 9.0+) and 6 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Alibaba vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Alibaba products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Alibaba Vulnerabilities
CyberStrike scans your infrastructure for Alibaba vulnerabilities and provides real-time remediation guidance.
Get Started