CVE-2022-23944
25.01.2022, 13:15
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.Enginsight
Vendor | Product | Version |
---|---|---|
apache | shenyu | 2.4.0 |
apache | shenyu | 2.4.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-862 - Missing AuthorizationThe software does not perform an authorization check when an actor attempts to access a resource or perform an action.
- CWE-306 - Missing Authentication for Critical FunctionThe product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
References