PT-2021-21721 · Apache · Apache Shenyu

·

CVE-2021-37580

·

Published

2021-11-16

·

Updated

2024-02-28

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache ShenYu versions 2.3.0 through 2.4.0
Description A flaw was found in Apache ShenYu Admin, where the incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication.
Recommendations For versions 2.3.0 and 2.4.0, update to a version that fixes the authentication bypass issue. As a temporary workaround, consider restricting access to the ShenyuAdminBootstrap component until a patch is available. Avoid using the JWT authentication mechanism in the affected Apache ShenYu versions until the issue is resolved.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37580
GHSA-VPFP-5GWQ-G533

Affected Products

Apache Shenyu