Apache
Apache Shenyu: vulnerabilidades y CVE
Apache Shenyu tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-25753 | Media (6.5) | 0.84% | — | 19 oct 2023 | There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manipulate arbitrary requests and retrieve corresponding responses by… |
| CVE-2022-42735 | Alta (8.8) | 1.2% | — | 15 feb 2023 | Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privilege low-level administrators create users with higher privileges than their own. This issue affects… |
| CVE-2022-37435 | Alta (8.8) | 1.3% | — | 1 sept 2022 | Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3. |
| CVE-2022-26650 | Alta (7.5) | 2.6% | — | 17 may 2022 | In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an… |
| CVE-2022-23945 | Alta (7.5) | 3.8% | — | 25 ene 2022 | Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1. |
| CVE-2022-23944 | Crítica (9.1) | 79% | — | 25 ene 2022 | User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1. |
| CVE-2022-23223 | Alta (7.5) | 4.3% | — | 25 ene 2022 | On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later. |
| CVE-2021-45029 | Crítica (9.8) | 6.0% | — | 25 ene 2022 | Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1. |
| CVE-2021-37580 | Crítica (9.8) | 42% | — | 16 nov 2021 | A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0 |