CVE-2022-23945
published 2022-01-25CVE-2022-23945: Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
3.77%
88.7th percentile
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | shenyu | — | — |
| apache | shenyu | — | — |
| apache_software_foundation | apache_shenyu | >= Apache ShenYu (incubating) < 2.4.2 | 2.4.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Missing authentication in ShenYu
ghsa·2022-01-28
CVE-2022-23945 [HIGH] CWE-306 Missing authentication in ShenYu
Missing authentication in ShenYu
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
OSV
Missing authentication in ShenYu
osv·2022-01-28
CVE-2022-23945 [HIGH] Missing authentication in ShenYu
Missing authentication in ShenYu
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2022/01/25/6http://www.openwall.com/lists/oss-security/2022/01/26/3https://lists.apache.org/thread/q2gg6ny6lpkph7nkrvjzqdvqpm805v8shttp://www.openwall.com/lists/oss-security/2022/01/25/6http://www.openwall.com/lists/oss-security/2022/01/26/3https://lists.apache.org/thread/q2gg6ny6lpkph7nkrvjzqdvqpm805v8s
2022-01-25
Published