PT-2022-1763 · Apache · Apache Shenyu
Zhang Yonglun
·
Published
2022-01-25
·
Updated
2023-10-16
·
CVE-2022-23223
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache ShenYu versions 2.4.0 through 2.4.1
Description
The issue is related to insufficient protection of registration data, allowing a remote attacker to obtain user registration data using a specially crafted HTTP request. This can lead to the disclosure of user passwords. The estimated number of potentially affected devices is not specified.
Recommendations
For Apache ShenYu versions 2.4.0 and 2.4.1, upgrade to version 2.4.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected endpoint to minimize the risk of exploitation. Avoid using the affected HTTP endpoint until the issue is resolved.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Shenyu