.. / CVE-2022-23944

Exploit for Apache ShenYu Admin Unauth Access (CVE-2022-23944)

Description:

Apache ShenYu suffers from an unauthorized access vulnerability where a user can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Nuclei Template

View the template here CVE-2022-23944.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-23944.yaml
Copy

References:

https://github.com/cckuailong/reapoc/blob/main/2022/CVE-2022-23944/vultarget/README.md
https://lists.apache.org/thread/dbrjnnlrf80dr0f92k5r2ysfvf1kr67y
https://nvd.nist.gov/vuln/detail/CVE-2022-23944
https://github.com/apache/incubator-shenyu/pull/2462
http://www.openwall.com/lists/oss-security/2022/01/25/15