QID 150540
Date Published: 2022-07-04
QID 150540: Apache ShenYu plugin API unauthenticated access (CVE-2022-23944)
Apache ShenYu is a Java native API Gateway for service proxy, protocol conversion and API governance.
Affected versions of Apache ShenYu suffers from an unauthorized access vulnerability where a user can access /plugin api without authentication.
Affected versions:
Apache ShenYu 2.4.0 and 2.4.1
QID Detection Logic (Unauthenticated) :
This QID sends a HTTP GET request to access "plugin" endpoint and based on the response determines if the target is vulnerable.
Successful exploitation of this vulnerability would allow an unauthorized remote attacker to access sensitive contents from /plugin endpoint.
Solution
Customers are advised to upgrade to Apache ShenYu version 2.4.2 or later to remediate this vulnerability.
Vendor References
- Apache ShenYu -
lists.apache.org/thread/dbrjnnlrf80dr0f92k5r2ysfvf1kr67y
CVEs related to QID 150540
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache ShenYu downloads |
|