Record summary

CVE-2022-23944 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListApache ShenYu (incubating) to < 2.4.2affected

org.apache.shenyu:shenyu-common

Browse Maven / org.apache.shenyu:shenyu-common
GitHub Advisory2.4.0 to < 2.4.2 · Fixed in 2.4.2affected

Nuclei templates

1
ProjectDiscoveryCRITICALApache ShenYu Admin Unauth AccessCVSS 9.1

Apache ShenYu suffers from an unauthorized access vulnerability where a user can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the Apache ShenYu admin panel.

Remediation

Upgrade to Apache ShenYu (incubating) 2.4.2 or apply the appropriate patch.

WeaknessesCWE-306CWE-862
Authorscckuakilong
Template tagscvecve2022shenyuunauthapachevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CPE: cpe:2.3:a:apache:shenyu:2.4.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

8