Severity
High
Analysis Summary
CVE-2021-37580
Apache ShenYu could allow a remote attacker to bypass security restrictions, caused by the incorrect use of JWT in ShenyuAdminBootstrap. By sending a specially-crafted request, an attacker could exploit this vulnerability to bypass access restrictions.
Impact
Security Bypass
Affected Vendors
Apache
Affected Products
- Apache ShenYu 2.2.1
Remediation
Upgrade to the latest version of Apache ShenYu, available from the Apache Web site.