Shenyu
Vendor:
First CVE: Nov 16, 2021 · Active for 4 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Shenyu over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 16, 2021
4 years ago
Most Recent CVE
Oct 19, 2023
1,008 days ago
CVE Severity & Scoring
Shenyu9 CVEs
11%
56%
33%
All CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (22.2%)
High0 (0.0%)
None7 (77.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23944CRITICAL User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | Jan 25, 2022 | 9.1 | 81 | NO | YES |
CVE-2021-37580CRITICAL A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2 | Nov 16, 2021 | 9.8 | 64 | NO | YES |
CVE-2021-45029CRITICAL Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | Jan 25, 2022 | 9.8 | 33 | NO | NO |
CVE-2022-42735HIGH Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu.
ShenYu Admin allows low-privilege low-level administrators create users with higher privi | Feb 15, 2023 | 8.8 | 28 | NO | NO |
CVE-2022-37435HIGH Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4. | Sep 1, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-23223HIGH On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later. | Jan 25, 2022 | 7.5 | 27 | NO | NO |
CVE-2022-26650HIGH In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllabl | May 17, 2022 | 7.5 | 24 | NO | NO |
CVE-2023-25753MEDIUM
There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manipulate arbitrary requests and r | Oct 19, 2023 | 6.5 | 21 | NO | NO |
CVE-2022-23945HIGH Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | Jan 25, 2022 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
22.2% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Shenyu
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.5.1 | 1 | 6.5 | 0.8% | 0 | 0 |
| 2.5.0 | 1 | 8.8 | 1.2% | 0 | 0 |
| 2.4.3 | 1 | 8.8 | 1.1% | 0 | 0 |
| 2.4.2 | 2 | 8.2 | 1.8% | 0 | 0 |
| 2.4.1 | 5 | 8.3 | 19.1% | 0 | 1 |
| 2.4.0 | 6 | 8.5 | 22.6% | 0 | 2 |
| 2.3.0 | 1 | 9.8 | 40.1% | 0 | 1 |