VendorsApacheshenyuall versions
Vulnerabilities

Apache Software Foundation

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2021-37580
Apache ShenYu Admin bypass JWT authentication
Published 2021-11-16 · Modified
9.8EPSS 0.419
CVE-2021-45029
Apache ShenYu 2.4.1 Groovy Code Injection & SpEL Injection
Published 2022-01-25 · Modified
9.8EPSS 0.060
CVE-2022-23944
Apache ShenYu 2.4.1 Improper access control
Published 2022-01-25 · Modified
9.1EPSS 0.790
CVE-2022-37435
Apache ShenYu Admin Improper Privilege Management
Published 2022-09-01 · Modified
8.8EPSS 0.013
CVE-2022-42735
Apache ShenYu Admin ultra vires
Published 2023-02-15 · Modified
8.8EPSS 0.012
CVE-2022-23223
Apache ShenYu Password leakage
Published 2022-01-25 · Modified
7.5EPSS 0.043
CVE-2022-23945
Apache ShenYu missing authentication allows gateway registration
Published 2022-01-25 · Modified
7.5EPSS 0.038
CVE-2022-26650
Apache ShenYu (incubating) Regular expression denial of service
Published 2022-05-17 · Modified
7.5EPSS 0.026
CVE-2023-25753
Server-Side Request Forgery in Apache ShenYu
Published 2023-10-19 · Modified
6.5EPSS 0.008