CVE-2022-37435

Severity
8.8HIGH
EPSS
0.5%
top 33.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 1
Latest updateSep 2

Description

Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

Mavenorg.apache.shenyu:shenyu-common2.4.22.5.0
NVDapache/shenyu2.4.2, 2.4.3+1
CVEListV5apache_software_foundation/apache_shenyuApache ShenYu 2.4.2 and 2.4.3

Patches

🔴Vulnerability Details

3
GHSA
Apache ShenYu Admin has insecure permissions2022-09-02
OSV
Apache ShenYu Admin has insecure permissions2022-09-02
CVEList
Apache ShenYu Admin Improper Privilege Management2022-09-01