Apache Software Foundation Apache Shenyu vulnerabilities
3 known vulnerabilities affecting apache_software_foundation/apache_shenyu.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-25753MEDIUMCVSS 6.5≤ 2.5.12023-10-19
CVE-2023-25753 [MEDIUM] CWE-918 CVE-2023-25753:
There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGatew
There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manipulate arbitrary requests and retrieve corresponding responses by inputting any URL into the requestUrl parameter.
Of particular concern is our ability to exert control over the HTTP method, cookies, IP
cvelistv5nvd
CVE-2022-42735HIGHCVSS 8.8≤ 2.5.02023-02-15
CVE-2022-42735 [HIGH] CWE-269 CVE-2022-42735: Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu.
ShenYu Ad
Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu.
ShenYu Admin allows low-privilege low-level administrators create users with higher privileges than their own.
This issue affects Apache ShenYu: 2.5.0.
Upgrade to Apache ShenYu 2.5.1 or apply patch https://github.com/apache/shenyu/pull/3958 https://github.com/
cvelistv5nvd
CVE-2022-37435HIGHCVSS 8.8vApache ShenYu 2.4.2 and 2.4.32022-09-01
CVE-2022-37435 [HIGH] CWE-732 CVE-2022-37435: Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify
Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3.
cvelistv5nvd