Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://lists.apache.org/thread/q2gg6ny6lpkph7nkrvjzqdvqpm805v8s | mailing list not applicable vendor advisory |
http://www.openwall.com/lists/oss-security/2022/01/25/6 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2022/01/26/3 | mailing list third party advisory patch |