CVE-2022-23944

CRITICAL NUCLEI

Apache ShenYu <2.4.1 - Info Disclosure

Title source: llm

Description

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Nuclei Templates (1)

Apache ShenYu Admin Unauth Access
CRITICALby cckuakilong

Scores

CVSS v3 9.1
EPSS 0.9024
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-862 CWE-306
Status published
Products (3)
apache/shenyu 2.4.0
apache/shenyu 2.4.1
org.apache.shenyu/shenyu-common 2.4.0 - 2.4.2Maven
Published Jan 25, 2022
Tracked Since Feb 18, 2026