CVE-2023-25753
- EPSS 0.57%
- Published 19.10.2023 09:15:08
- Last modified 21.11.2024 07:50:04
There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manipulate arbitrary requests and retrieve corresponding responses by inputting any URL into the requestU...
CVE-2022-42735
- EPSS 0.24%
- Published 15.02.2023 10:15:16
- Last modified 19.03.2025 16:15:16
Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privilege low-level administrators create users with higher privileges than their own. This issue affects Apache ShenYu: 2.5.0. Upgra...
CVE-2022-37435
- EPSS 0.19%
- Published 01.09.2022 14:15:10
- Last modified 21.11.2024 07:14:59
Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3.
CVE-2022-26650
- EPSS 1.26%
- Published 17.05.2022 08:15:06
- Last modified 21.11.2024 06:54:15
In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular ex...
CVE-2022-23223
- EPSS 4.68%
- Published 25.01.2022 13:15:08
- Last modified 21.11.2024 06:48:13
On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later.
CVE-2022-23944
- EPSS 90.56%
- Published 25.01.2022 13:15:08
- Last modified 21.11.2024 06:49:30
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
CVE-2022-23945
- EPSS 1.13%
- Published 25.01.2022 13:15:08
- Last modified 21.11.2024 06:49:30
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
CVE-2021-45029
- EPSS 5.34%
- Published 25.01.2022 13:15:07
- Last modified 21.11.2024 06:31:49
Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
CVE-2021-37580
- EPSS 93.69%
- Published 16.11.2021 10:15:07
- Last modified 21.11.2024 06:15:27
A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0