CVE-2022-23223

On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later.
References
Link Resource
http://www.openwall.com/lists/oss-security/2022/01/25/7 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2022/01/26/4 Exploit Mailing List Patch Third Party Advisory
https://lists.apache.org/thread/q2gg6ny6lpkph7nkrvjzqdvqpm805v8s Mailing List Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:shenyu:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:shenyu:2.4.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-01-25 13:15

Updated : 2023-10-16 18:22


NVD link : CVE-2022-23223

Mitre link : CVE-2022-23223

CVE.ORG link : CVE-2022-23223


JSON object : View

Products Affected

apache

  • shenyu
CWE
CWE-522

Insufficiently Protected Credentials