Description
On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later.
Remediation
References
http://www.openwall.com/lists/oss-security/2022/01/25/7
http://www.openwall.com/lists/oss-security/2022/01/26/4
https://lists.apache.org/thread/q2gg6ny6lpkph7nkrvjzqdvqpm805v8s
Related Vulnerabilities
CVE-2020-15125 Vulnerability in npm package auth0
CVE-2023-46589 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2020-6506 Vulnerability in npm package react-native-webview
CVE-2022-0654 Vulnerability in npm package requestretry
CVE-2020-36181 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind