PT-2022-1573 · Apache · Apache Shenyu

Zhang Yonglun

·

Published

2022-01-25

·

Updated

2022-01-28

·

CVE-2021-45029

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache ShenYu versions 2.4.0 through 2.4.1
Description The issue is related to incorrect code generation management, which can be exploited to execute arbitrary code using Groovy Code injection or SpEL injection, leading to Remote Code Execution. This can be done by a remote attacker.
Recommendations For Apache ShenYu versions 2.4.0 and 2.4.1, consider disabling Groovy Code injection and SpEL injection functionality until a patch is available. Restrict access to the affected components to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00791
CVE-2021-45029
GHSA-GH38-X2WM-XMC8

Affected Products

Apache Shenyu