High severity8.8NVD Advisory· Published Sep 1, 2022· Updated Jun 17, 2026
CVE-2022-37435
CVE-2022-37435
Description
Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.shenyu:shenyu-commonMaven | >= 2.4.2, < 2.5.0 | 2.5.0 |
Affected products
2Patches
Vulnerability mechanics
References
5- lists.apache.org/thread/ndblyxr2fdrvjtgbs1bogxgv2cgk7t28nvdMailing ListPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-fjjw-82xw-vfc2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-37435ghsaADVISORY
- github.com/apache/shenyu/pull/3658ghsaWEB
- github.com/apache/shenyu/releases/tag/v2.5.0ghsaWEB
News mentions
0No linked articles in our index yet.