ID

VAR-202111-0822


CVE

CVE-2021-37580


TITLE

Apache ShenYu Admin  Authentication vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2021-015197

DESCRIPTION

A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0. Apache ShenYu Admin There is an authentication vulnerability in.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Apache ShenYu is an asynchronous, high-performance, cross-language, and responsive API gateway of the Apache Foundation. No detailed vulnerability details are currently provided

Trust: 2.25

sources: NVD: CVE-2021-37580 // JVNDB: JVNDB-2021-015197 // CNVD: CNVD-2021-89682 // VULMON: CVE-2021-37580

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-89682

AFFECTED PRODUCTS

vendor:apachemodel:shenyuscope:eqversion:2.3.0

Trust: 2.4

vendor:apachemodel:shenyuscope:eqversion:2.4.0

Trust: 2.4

vendor:apachemodel:shenyuscope:eqversion: -

Trust: 0.8

sources: CNVD: CNVD-2021-89682 // JVNDB: JVNDB-2021-015197 // NVD: CVE-2021-37580

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2021-37580
value: CRITICAL

Trust: 1.0

NVD: CVE-2021-37580
value: CRITICAL

Trust: 0.8

CNVD: CNVD-2021-89682
value: HIGH

Trust: 0.6

CNNVD: CNNVD-202111-1500
value: CRITICAL

Trust: 0.6

VULMON: CVE-2021-37580
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2021-37580
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

CNVD: CNVD-2021-89682
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2021-37580
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2021-37580
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2021-89682 // VULMON: CVE-2021-37580 // JVNDB: JVNDB-2021-015197 // CNNVD: CNNVD-202111-1500 // NVD: CVE-2021-37580

PROBLEMTYPE DATA

problemtype:CWE-287

Trust: 1.0

problemtype:Inappropriate authentication (CWE-287) [NVD evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2021-015197 // NVD: CVE-2021-37580

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202111-1500

TYPE

authorization issue

Trust: 0.6

sources: CNNVD: CNNVD-202111-1500

PATCH

title:CVE-2021-37580url:https://lists.apache.org/thread/o15j25qwtpcw62k48xw1tnv48skh3zgb

Trust: 0.8

title:Patch for Apache ShenYu authorization issue vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/300116

Trust: 0.6

title:Apache ShenYu Remediation measures for authorization problem vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=170134

Trust: 0.6

title:CVE-2021-37580url:https://github.com/Liang2580/CVE-2021-37580

Trust: 0.1

title:CVE-2021-37580url:https://github.com/fengwenhua/CVE-2021-37580

Trust: 0.1

title:CVE-2021-37580url:https://github.com/rabbitsafe/CVE-2021-37580

Trust: 0.1

title:westone-CVE-2021-37580-scannerurl:https://github.com/Osyanina/westone-CVE-2021-37580-scanner

Trust: 0.1

title:CVE-2021-37580url:https://github.com/Wing-song/CVE-2021-37580

Trust: 0.1

title:CVE-2021-37580url:https://github.com/ZororoZ/CVE-2021-37580

Trust: 0.1

title:langligelangurl:https://github.com/langligelang/langligelang

Trust: 0.1

title:db_script_v2url:https://github.com/Ilovewomen/db_script_v2

Trust: 0.1

title:db_script_v2_2url:https://github.com/Ilovewomen/db_script_v2_2

Trust: 0.1

sources: CNVD: CNVD-2021-89682 // VULMON: CVE-2021-37580 // JVNDB: JVNDB-2021-015197 // CNNVD: CNNVD-202111-1500

EXTERNAL IDS

db:NVDid:CVE-2021-37580

Trust: 3.9

db:OPENWALLid:OSS-SECURITY/2021/11/16/1

Trust: 1.7

db:JVNDBid:JVNDB-2021-015197

Trust: 0.8

db:CNVDid:CNVD-2021-89682

Trust: 0.6

db:CNNVDid:CNNVD-202111-1500

Trust: 0.6

db:VULMONid:CVE-2021-37580

Trust: 0.1

sources: CNVD: CNVD-2021-89682 // VULMON: CVE-2021-37580 // JVNDB: JVNDB-2021-015197 // CNNVD: CNNVD-202111-1500 // NVD: CVE-2021-37580

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2021-37580

Trust: 2.1

url:https://lists.apache.org/thread/o15j25qwtpcw62k48xw1tnv48skh3zgb

Trust: 1.7

url:http://www.openwall.com/lists/oss-security/2021/11/16/1

Trust: 1.7

url:https://cwe.mitre.org/data/definitions/287.html

Trust: 0.1

url:https://github.com/liang2580/cve-2021-37580

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: CNVD: CNVD-2021-89682 // VULMON: CVE-2021-37580 // JVNDB: JVNDB-2021-015197 // CNNVD: CNNVD-202111-1500 // NVD: CVE-2021-37580

SOURCES

db:CNVDid:CNVD-2021-89682
db:VULMONid:CVE-2021-37580
db:JVNDBid:JVNDB-2021-015197
db:CNNVDid:CNNVD-202111-1500
db:NVDid:CVE-2021-37580

LAST UPDATE DATE

2024-08-14T13:53:47.025000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-89682date:2021-11-22T00:00:00
db:VULMONid:CVE-2021-37580date:2021-11-17T00:00:00
db:JVNDBid:JVNDB-2021-015197date:2022-11-11T05:28:00
db:CNNVDid:CNNVD-202111-1500date:2021-11-25T00:00:00
db:NVDid:CVE-2021-37580date:2021-11-17T20:17:30.813

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-89682date:2021-11-22T00:00:00
db:VULMONid:CVE-2021-37580date:2021-11-16T00:00:00
db:JVNDBid:JVNDB-2021-015197date:2022-11-11T00:00:00
db:CNNVDid:CNNVD-202111-1500date:2021-11-16T00:00:00
db:NVDid:CVE-2021-37580date:2021-11-16T10:15:07.220