CVE-2022-23223
HIGHApache ShenYu 2.4.0-2.4.1 - Unauthenticated Password Disclosure
Title source: llmDescription
On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later.
References (3)
Core 3
Core References
Mailing List, Vendor Advisory x_refsource_misc
https://lists.apache.org/thread/q2gg6ny6lpkph7nkrvjzqdvqpm805v8s
Mailing List, Third Party Advisory mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/01/25/7
Exploit, Mailing List, Patch, Third Party Advisory mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/01/26/4
Scores
CVSS v3
7.5
EPSS
0.0455
EPSS Percentile
89.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-522
Status
published
Products (3)
apache/shenyu
2.4.0
apache/shenyu
2.4.1
org.apache.shenyu/shenyu-common
2.4.0 - 2.4.2Maven
Published
Jan 25, 2022
Tracked Since
Feb 18, 2026