CVE-2022-42735

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
15/02/2023
Last modified:
19/03/2025

Description

Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu.<br /> <br /> <br /> ShenYu Admin allows low-privilege low-level administrators create users with higher privileges than their own.<br /> <br /> This issue affects Apache ShenYu: 2.5.0.<br /> <br /> Upgrade to Apache ShenYu 2.5.1 or apply patch https://github.com/apache/shenyu/pull/3958 https://github.com/apache/shenyu/pull/3958 .<br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:shenyu:2.5.0:*:*:*:*:*:*:*