Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-23553
HistoryFeb 17, 2023 - 12:00 a.m.

Apache ShenYu License Issue Vulnerability (CNVD-2023-23553)

2023-02-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
apache foundation
api gateway
authorization issue
privilege management
vulnerability

EPSS

0.002

Percentile

61.2%

Apache ShenYu, an asynchronous, high-performance, cross-language, responsive API gateway from the Apache Foundation, is vulnerable to authorization issues in versions prior to Apache ShenYu 2.5.1. The vulnerability stems from the presence of improper privilege management, which could be exploited by a low-privilege attacker to create users with higher privileges than their own.

EPSS

0.002

Percentile

61.2%