GHSA-vpfp-5gwq-g533
Dashboard / Vulnerabilities / GHSA-vpfp-5gwq-g533
Summary: Improper Authentication in Apache ShenYu Admin
Details: A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-37580, https://github.com/apache/shenyu/commit/f78adb26926ba53b4ec5c21f2cf7e931461d601d, https://github.com/apache/shenyu, https://github.com/apache/shenyu/releases/tag/v2.4.1, https://lists.apache.org/thread/o15j25qwtpcw62k48xw1tnv48skh3zgb, http://www.openwall.com/lists/oss-security/2021/11/16/1
Affected packages
Package
Name: org.apache.shenyu:shenyu-admin
Purl: pkg:maven/org.apache.shenyu/shenyu-admin
Affected ranges
Type: ECOSYSTEM
Events:
