CVE-2021-37580
Improper Authentication in Apache ShenYu Admin
9.8
CRITICAL
CVSS 3.1
EPSS 40.1%
Description
A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0.
How to fix CVE-2021-37580
To remediate CVE-2021-37580, upgrade the affected package to a fixed version below.
- Maven/org.apache.shenyu:shenyu-admin—upgrade to 2.4.1 or later
Is CVE-2021-37580 being exploited?
Moderate — EPSS is 40.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 2.3.0, < 2.4.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |