High severity8.8NVD Advisory· Published Feb 15, 2023· Updated Jun 17, 2026
CVE-2022-42735
CVE-2022-42735
Description
Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu.
ShenYu Admin allows low-privilege low-level administrators create users with higher privileges than their own.
This issue affects Apache ShenYu: 2.5.0.
Upgrade to Apache ShenYu 2.5.1 or apply patch https://github.com/apache/shenyu/pull/3958 https://github.com/apache/shenyu/pull/3958 .
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.shenyu:shenyu-adminMaven | < 2.5.1 | 2.5.1 |
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-vf8h-2wwj-jq22ghsaADVISORY
- lists.apache.org/thread/2k8764jmckmc19qc8x51nlnngq71pcf7nvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-42735ghsaADVISORY
- github.com/apache/shenyu/pull/3958ghsaWEB
News mentions
0No linked articles in our index yet.