7.5
CVSSv3

CVE-2022-23945

Published: 25/01/2022 Updated: 01/02/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache shenyu 2.4.0

apache shenyu 2.4.1

Mailing Lists

Description: Missing authentication on ShenYu Admin when register by HTTP This issue affected Apache ShenYu 240 and 241 -- Zhang Yonglun Apache ShenYu (Incubating) Apache ShardingSphere ...
Severity: moderate Description: Missing authentication on ShenYu Admin when a gateway registers So, if ShenYu Admin is exposed to the internet, it will allow any user to register as the gateway This issue affects Apache ShenYu (incubating) 240 and 241 Mitigation: Upgrade to Apache ShenYu (incubating) 242 or apply patch github ...