First published: Tue Jan 25 2022(Updated: )
Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache ShenYu | =2.4.0 | |
Apache ShenYu | =2.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45029 is a vulnerability in Apache ShenYu 2.4.0 and 2.4.1 that allows for Groovy Code Injection & SpEL Injection leading to Remote Code Execution.
CVE-2021-45029 has a severity of 9.8 (Critical).
CVE-2021-45029 affects Apache ShenYu versions 2.4.0 and 2.4.1.
CVE-2021-45029 can be exploited by injecting malicious Groovy code or SpEL (Spring Expression Language) code, which allows for remote code execution.
Yes, you can find references for CVE-2021-45029 at the following URLs: [reference 1](http://www.openwall.com/lists/oss-security/2022/01/25/8), [reference 2](http://www.openwall.com/lists/oss-security/2022/01/26/1), [reference 3](https://lists.apache.org/thread/3zzmwvg3012tg306x8o893fvdcssx639).