Vulnerabilities > Apache > Shenyu

DATE CVE VULNERABILITY TITLE RISK
2023-10-19 CVE-2023-25753 Server-Side Request Forgery (SSRF) vulnerability in Apache Shenyu 2.5.1
There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint.
network
low complexity
apache CWE-918
6.5
2023-02-15 CVE-2022-42735 Improper Privilege Management vulnerability in Apache Shenyu 2.5.0
Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privilege low-level administrators create users with higher privileges than their own. This issue affects Apache ShenYu: 2.5.0. Upgrade to Apache ShenYu 2.5.1 or apply patch https://github.com/apache/shenyu/pull/3958 https://github.com/apache/shenyu/pull/3958 .
network
low complexity
apache CWE-269
8.8
2022-09-01 CVE-2022-37435 Incorrect Permission Assignment for Critical Resource vulnerability in Apache Shenyu 2.4.2/2.4.3
Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords.
network
low complexity
apache CWE-732
8.8
2022-05-17 CVE-2022-26650 Unspecified vulnerability in Apache Shenyu 2.4.0/2.4.1/2.4.2
In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user.
network
low complexity
apache
7.5
2022-01-25 CVE-2021-45029 Code Injection vulnerability in Apache Shenyu 2.4.0/2.4.1
Groovy Code Injection & SpEL Injection which lead to Remote Code Execution.
network
low complexity
apache CWE-94
7.5
2022-01-25 CVE-2022-23223 Insufficiently Protected Credentials vulnerability in Apache Shenyu 2.4.0/2.4.1
On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users.
network
low complexity
apache CWE-522
7.5
2022-01-25 CVE-2022-23944 Missing Authentication for Critical Function vulnerability in Apache Shenyu 2.4.0/2.4.1
User can access /plugin api without authentication.
network
low complexity
apache CWE-306
6.4
2022-01-25 CVE-2022-23945 Missing Authentication for Critical Function vulnerability in Apache Shenyu 2.4.0/2.4.1
Missing authentication on ShenYu Admin when register by HTTP.
network
low complexity
apache CWE-306
5.0
2021-11-16 CVE-2021-37580 Improper Authentication vulnerability in Apache Shenyu 2.3.0/2.4.0
A flaw was found in Apache ShenYu Admin.
network
low complexity
apache CWE-287
7.5