CVE-2022-23223

HIGH

Apache ShenYu 2.4.0-2.4.1 - Unauthenticated Password Disclosure

Title source: llm
STIX 2.1

Description

On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later.

References (3)

Core 3
Core References
Mailing List, Vendor Advisory x_refsource_misc
https://lists.apache.org/thread/q2gg6ny6lpkph7nkrvjzqdvqpm805v8s
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/01/25/7
Exploit, Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/01/26/4

Scores

CVSS v3 7.5
EPSS 0.0455
EPSS Percentile 89.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-522
Status published
Products (3)
apache/shenyu 2.4.0
apache/shenyu 2.4.1
org.apache.shenyu/shenyu-common 2.4.0 - 2.4.2Maven
Published Jan 25, 2022
Tracked Since Feb 18, 2026