Lucene search

K
nvd[email protected]NVD:CVE-2022-37435
HistorySep 01, 2022 - 2:15 p.m.

CVE-2022-37435

2022-09-0114:15:10
CWE-732
web.nvd.nist.gov
4
apache shenyu
insecure permissions
low-privilege admins
high-privilege passwords
apache shenyu 2.4.2
apache shenyu 2.4.3

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

44.5%

Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator’s passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3.

Affected configurations

Nvd
Node
apacheshenyuMatch2.4.2
OR
apacheshenyuMatch2.4.3
VendorProductVersionCPE
apacheshenyu2.4.2cpe:2.3:a:apache:shenyu:2.4.2:*:*:*:*:*:*:*
apacheshenyu2.4.3cpe:2.3:a:apache:shenyu:2.4.3:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

44.5%

Related for NVD:CVE-2022-37435