CVE-2022-37435: Apache Shenyu
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3.
Affected products
- Apache Shenyu: version 2.4.2 only; version 2.4.3 only
Published 2022-09-01. Last modified 2026-06-17.