First published: Tue Jan 25 2022(Updated: )
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache ShenYu | =2.4.0 | |
Apache ShenYu | =2.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23944 is a vulnerability that allows users to access the /plugin API without authentication in Apache ShenYu 2.4.0 and 2.4.1.
The severity of CVE-2022-23944 is critical with a score of 9.1.
CVE-2022-23944 affects Apache ShenYu 2.4.0 and 2.4.1 by allowing users to access the /plugin API without authentication.
Yes, you can find references for CVE-2022-23944 at the following URLs: [http://www.openwall.com/lists/oss-security/2022/01/25/15](http://www.openwall.com/lists/oss-security/2022/01/25/15), [http://www.openwall.com/lists/oss-security/2022/01/25/5](http://www.openwall.com/lists/oss-security/2022/01/25/5), [http://www.openwall.com/lists/oss-security/2022/01/26/2](http://www.openwall.com/lists/oss-security/2022/01/26/2)
To fix CVE-2022-23944 in Apache ShenYu, it is recommended to upgrade to a version that includes the necessary security patches.