Description
Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3.
Remediation
References
https://lists.apache.org/thread/ndblyxr2fdrvjtgbs1bogxgv2cgk7t28
Related Vulnerabilities
CVE-2023-28628 Vulnerability in maven package lambdaisland:uri
CVE-2022-28220 Vulnerability in maven package org.apache.james.protocols:protocols-api
CVE-2021-31805 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2023-37953 Vulnerability in maven package com.mabl.integration.jenkins:mabl-integration
CVE-2019-10427 Vulnerability in maven package org.jenkins-ci.plugins:aqua-microscanner