← back
CVE-2021-37580observed exploitationCWE-287

Apache ShenYu Admin bypass JWT authentication

72Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 40%
from disclosure to weapon1 days
Published on NVDNov 16
1st PoC+1d
VulnCheck+749d
exploitation probability
40%top 2% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.