S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-23944 Scanner

Detects 'Improper Access Control' vulnerability in Apache ShenYu affects v. 2.4.0 and 2.4.1.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-23944
9.1
CVSS

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Apache ShenYu (incubating)by Apache Software Foundation
AFFECTED< 2.4.2SAFE ✓≥ 2.4.2
Updated Aug 19, 2026View on NVD →
Detail

Apache ShenYu is an open-source project that helps to manage and orchestrate cloud-native micro-services and APIs. It provides a comprehensive and centralized way to manage multiple APIs and micro-services in one place, supporting things like traffic control, service registry, service discovery, and security. The platform is designed to make it easier to build and manage complex applications in a distributed system environment.

CVE-2022-23944 is a vulnerability that was recently detected in Apache ShenYu versions 2.4.0 and 2.4.1. The vulnerability allows unauthorized users to access the /plugin API endpoint without any authentication. This means that anyone can access this endpoint and potentially execute arbitrary code or modify the system's configuration.

The exploitation of this vulnerability can lead to various issues. Firstly, it may provide hackers with unauthorized access to sensitive resources, including personal and confidential information, among others. Secondly, attackers can exploit this vulnerability to launch distributed denial of service (DDoS) attacks or even take control of the system to launch further attacks.

In conclusion, managing API and micro-services with Apache ShenYu comes with its advantages but vulnerabilities like CVE-2022-23944 can put an organization's digital assets at risk. Fortunately, it is possible to detect such vulnerabilities and fix them before they are exploited using different methods, including using the pro features of s4e.io to quickly learn about vulnerabilities in your digital assets. It is always advisable to keep all software applications updated with the latest patches supported by the vendor.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users of Apache ShenYu should take the following precautions:

  • Update to the newest version of Apache ShenYu, which has a fix for the vulnerability.
  • Configure the Apache ShenYu server to require authentication for the /plugin API endpoint.
  • Regularly monitor logs for any suspicious activity related to the /plugin API endpoint.
  • Configure network security measures, e.g., a firewall, to filter out traffic targeting Apache ShenYu.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.