CVE-2021-37580
CRITICAL EXPLOITED NUCLEIApache Shenyu < 2.4.1 - Authentication Bypass
Title source: ruleDescription
A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0
Exploits (7)
nomisec
WORKING POC
1 stars
by CN016 · remote
https://github.com/CN016/Apache-ShenYu-Admin-JWT-CVE-2021-37580-
Nuclei Templates (1)
Apache ShenYu Admin JWT - Authentication Bypass
CRITICALby pdteam
Scores
CVSS v3
9.8
EPSS
0.9399
EPSS Percentile
99.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2023-12-05
CWE
CWE-287
Status
published
Products (3)
apache/shenyu
2.3.0
apache/shenyu
2.4.0
org.apache.shenyu/shenyu-admin
2.3.0 - 2.4.1Maven
Published
Nov 16, 2021
Tracked Since
Feb 18, 2026