S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-37580 Scanner

CVE-2021-37580 scanner - Authentication Bypass vulnerability in Apache ShenYu Admin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-37580
9.8
CVSS

A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache ShenYu Adminby Apache Software Foundation
Apache ShenYu Admin 2.3.0-2.4.0
Updated Aug 21, 2026View on NVD →
Detail

Apache ShenYu Admin is a software management tool that is predominantly used by enterprises to manage their IT infrastructure. This tool is highly versatile, allowing users to monitor network policies, configure gateway settings, and a host of other IT administrative tasks. Through these functionalities, Apache ShenYu Admin helps organizations optimize their networks, minimize network downtimes, and ensure high network performance. 

Recently, a significant vulnerability in Apache ShenYu Admin was detected, identified as CVE-2021-37580. The flaw involves the incorrect use of JSON Web Tokens (JWT) in ShenyuAdminBootstrap, which renders the software susceptible to a serious security breach. As a result, hackers can exploit the vulnerability to bypass the tool's authentication process, ultimately gaining unauthorized access to sensitive IT infrastructure data. 

When exploited, the CVE-2021-37580 vulnerability can lead to several adverse consequences. Hackers can gain unrestricted access to user accounts, allowing them to gain access to critical business data. Additionally, they can deploy malware or ransomware through the system, leading to business disruptions and even loss of data. If left unaddressed, the vulnerability can cause significant damage to an organization, putting it at risk of financial losses, regulatory sanctions, and reputational damage.

With the pro features of the s4e.io platform, users can stay informed and up-to-date with the latest security vulnerabilities in their digital assets. By leveraging the platform's comprehensive vulnerability database, users can monitor their systems for any potential security risks proactively. Furthermore, the platform offers useful security recommendations and mitigation strategies to help mitigate identified vulnerabilities, ultimately safeguarding users against potential cyber attacks. 

 

REFERENCES

Solution Advice

To safeguard against this vulnerability, users are advised to take the following precautions: 

  • Update Apache ShenYu Admin to the latest version immediately
  • Regularly monitor network traffic for any signs of unauthorized access
  • Strengthen network security by deploying additional security measures, such as two-factor authentication, intrusion detection systems, and firewalls
  • Conduct regular security audits to identify potential vulnerabilities before they are exploited.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.