PT-2022-1758 · Apache · Apache Shenyu

Zhang Yonglun

·

Published

2022-01-25

·

Updated

2022-02-01

·

CVE-2022-23945

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache ShenYu versions 2.4.0 through 2.4.1
Description The issue is related to missing authentication on ShenYu Admin when registering by HTTP, which can allow a remote attacker to bypass security restrictions.
Recommendations For Apache ShenYu versions 2.4.0 and 2.4.1, consider disabling the HTTP registration functionality until a patch is available. Restrict access to the ShenYu Admin module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01056
CVE-2022-23945
GHSA-7RJP-FGWJ-47RW

Affected Products

Apache Shenyu