Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-18269
HistoryJan 27, 2022 - 12:00 a.m.

Apache ShenYu Access Control Error Vulnerability (CNVD-2022-18269)

2022-01-2700:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
apache shenyu
access control
vulnerability
versions 2.4.0 and 2.4.1
authentication
http
attacker
unauthorized access
system data
functionality
cnvd-2022-18269

EPSS

0.003

Percentile

70.3%

Apache ShenYu, an asynchronous, high-performance, cross-language, responsive API gateway from the Apache Foundation, is vulnerable to an access control error in Apache ShenYu versions 2.4.0 and 2.4.1, which stems from a lack of authentication in ShenYu Admin when registering via HTTP. An attacker could exploit this vulnerability to cause unauthorized access to system data or functionality.

EPSS

0.003

Percentile

70.3%