Shenyu

Vendor:

First CVE: Nov 16, 2021 · Active for 4 years

9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Shenyu over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 16, 2021
4 years ago
Most Recent CVE
Oct 19, 2023
1,008 days ago

CVE Severity & Scoring

Shenyu9 CVEs
All CVEs352,101 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None7 (77.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Jan 25, 20229.181NOYES
A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2
Nov 16, 20219.864NOYES
Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Jan 25, 20229.833NONO
Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privilege low-level administrators create users with higher privi
Feb 15, 20238.828NONO
Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.
Sep 1, 20228.828NONO
On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later.
Jan 25, 20227.527NONO
In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllabl
May 17, 20227.524NONO
There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manipulate arbitrary requests and r
Oct 19, 20236.521NONO
Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
Jan 25, 20227.520NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
22.2% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Shenyu

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.5.116.50.8%00
2.5.018.81.2%00
2.4.318.81.1%00
2.4.228.21.8%00
2.4.158.319.1%01
2.4.068.522.6%02
2.3.019.840.1%01