Description
Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3.
Remediation
References
https://lists.apache.org/thread/ndblyxr2fdrvjtgbs1bogxgv2cgk7t28
Related Vulnerabilities
CVE-2022-24785 Vulnerability in npm package moment
CVE-2020-11971 Vulnerability in maven package org.apache.camel:camel-core
CVE-2021-39150 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2023-42278 Vulnerability in maven package cn.hutool:hutool-json
CVE-2023-50730 Vulnerability in maven package edu.gemini:gsp-graphql-core_sjs1_2.13