[oss-security] 20220125 Re: CVE-2022-23944: Apache ShenYu 2.4.1 Improper access controlmailing list
http://www.openwall.com/lists/oss-security/2022/01/25/15 CVE-2022-23944
CRITICALNuclei
Apache ShenYu 2.4.1 Improper access control
Record summary
CVE-2022-23944 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.
Description
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Apache ShenYu (incubating)Browse Apache Software Foundation / Apache ShenYu (incubating) | CVE List | Apache ShenYu (incubating) to < 2.4.2 | affected |
org.apache.shenyu:shenyu-commonBrowse Maven / org.apache.shenyu:shenyu-common | GitHub Advisory | 2.4.0 to < 2.4.2 · Fixed in 2.4.2 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALApache ShenYu Admin Unauth AccessCVSS 9.1
Apache ShenYu suffers from an unauthorized access vulnerability where a user can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the Apache ShenYu admin panel.
Remediation
Upgrade to Apache ShenYu (incubating) 2.4.2 or apply the appropriate patch.
WeaknessesCWE-306CWE-862
Authorscckuakilong
Template tagscvecve2022shenyuunauthapachevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CPE: cpe:2.3:a:apache:shenyu:2.4.0:*:*:*:*:*:*:*
https://github.com/apache/incubator-shenyu/pull/2462 https://nvd.nist.gov/vuln/detail/CVE-2022-23944 https://github.com/cckuailong/reapoc/blob/main/2022/CVE-2022-23944/vultarget/README.md https://lists.apache.org/thread/dbrjnnlrf80dr0f92k5r2ysfvf1kr67y http://www.openwall.com/lists/oss-security/2022/01/25/15
Source: ProjectDiscovery
References
8[oss-security] 20220125 CVE-2022-23944: Apache ShenYu 2.4.1 Improper access controlmailing list
http://www.openwall.com/lists/oss-security/2022/01/25/5 [oss-security] 20220126 CVE-2022-23944: Apache ShenYu (incubating) Improper access controlmailing list
http://www.openwall.com/lists/oss-security/2022/01/26/2 github.com
https://github.com/apache/incubator-shenyu github.com
https://github.com/apache/incubator-shenyu/pull/2462 github.com
https://github.com/apache/shenyu/pull/2462/commits/50e4b5e626ad94b415e26ef4fbe584bd51fd1b77 lists.apache.org
https://lists.apache.org/thread/dbrjnnlrf80dr0f92k5r2ysfvf1kr67y nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-23944