PT-2022-1758 · Apache · Apache Shenyu

·

CVE-2022-23945

·

Published

2022-01-25

·

Updated

2022-02-01

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache ShenYu versions 2.4.0 through 2.4.1
Description The issue is related to missing authentication on ShenYu Admin when registering by HTTP, which can allow a remote attacker to bypass security restrictions.
Recommendations For Apache ShenYu versions 2.4.0 and 2.4.1, consider disabling the HTTP registration functionality until a patch is available. Restrict access to the ShenYu Admin module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01056
CVE-2022-23945
GHSA-7RJP-FGWJ-47RW

Affected Products

Apache Shenyu