First published: Wed Feb 15 2023(Updated: )
Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privilege low-level administrators create users with higher privileges than their own. This issue affects Apache ShenYu: 2.5.0. Upgrade to Apache ShenYu 2.5.1 or apply patch https://github.com/apache/shenyu/pull/3958 https://github.com/apache/shenyu/pull/3958 .
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache ShenYu | =2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42735 is an Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu.
CVE-2022-42735 has a severity rating of 8.8 (high).
CVE-2022-42735 allows low-privilege low-level administrators in Apache ShenYu to create users with higher privileges than their own.
Apache ShenYu version 2.5.0 is affected by CVE-2022-42735.
To fix CVE-2022-42735, upgrade to Apache ShenYu 2.5.1 or apply the provided patch.