RULE(RULE ID:334169)

Rule General Information
Release Date: 2021-11-23
Rule Name: Apache ShenYu JWT Authentication Bypass Vulnerability (CVE-2021-37580)
Severity:
CVE ID:
Rule Protection Details
Description: Apache ShenYu is an asynchronous, high-performance, cross-language, and responsive API gateway of Apache. Apache ShenYu Admin has an authorization issue vulnerability, which stems from the incorrect use of JWT in ShenyuAdminBootstrap that allows attackers to bypass authentication.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: http://www.openwall.com/lists/oss-security/2021/11/16/1
https://lists.apache.org/thread/o15j25qwtpcw62k48xw1tnv48skh3zgb
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://lists.apache.org/thread/o15j25qwtpcw62k48xw1tnv48skh3zgb