[MAVEN:GHSA-VPFP-5GWQ-G533] Improper Authentication in Apache ShenYu Admin

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0.

Package Affected Version
pkg:maven/org.apache.shenyu/shenyu-admin >= 2.3.0, < 2.4.1
Package Fixed Version
pkg:maven/org.apache.shenyu/shenyu-admin = 2.4.1
ID
MAVEN:GHSA-VPFP-5GWQ-G533
Severity
critical
URL
https://github.com/advisories/GHSA-vpfp-5gwq-g533
Published
2021-11-17T23:15:30
(2 years ago)
Modified
2023-09-05T22:18:19
(12 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.shenyu/shenyu-admin org.apache.shenyu shenyu-admin >= 2.3.0 < 2.4.1
Fixed pkg:maven/org.apache.shenyu/shenyu-admin org.apache.shenyu shenyu-admin = 2.4.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...