PoC Index

CVE-2021-37580

CRITICAL 9.8EPSS 40.1%

A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
40.06% chance of exploitation in the next 30 days, 99th percentile
Nuclei
critical · CWE-287
Published
2021-11-16
Updated
2024-08-04

Proof-of-concept exploits (7)

Nuclei templates (1)

Exploit collections (1)

References

Related