Vulnerability record · CVE-2022-23944 · published 25 January 2022
CVE-2022-23944: Apache ShenYu plugin API missing authentication
Apache · Shenyu
Apache ShenYu 2.4.0 and 2.4.1 expose the /plugin API without requiring authentication, a missing authorization and missing authentication flaw. Because the endpoint is reachable over the network with no credentials, it matters for any deployment of the affected versions.
Description
User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityCVSS 9.1 with network reachability, no authentication and no user interaction, plus a very high EPSS probability, makes this an urgent exposure for affected ShenYu deployments.
What it is
Apache ShenYu 2.4.0 and 2.4.1 expose the /plugin API without requiring authentication, a missing authorization and missing authentication flaw. Because the endpoint is reachable over the network with no credentials, it matters for any deployment of the affected versions.
Impact
An unauthenticated attacker can reach the /plugin API and act with the privileges the endpoint grants, affecting confidentiality and integrity of the gateway configuration. The CVSS vector shows no availability impact.
Attack surface
Reached over the network via HTTP against the /plugin API path; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is very high at 0.79007 (percentile 0.99576), and references include a patch advisory but no public exploit tag.
What to do
- Upgrade Apache ShenYu past 2.4.1 to a release containing the fix referenced in the patch advisory
- If upgrade is not immediate, block external access to the /plugin API at the reverse proxy or gateway
- Restrict ShenYu admin and plugin endpoints to trusted management networks only
- Audit gateway configuration and plugin settings for unauthorized changes made before remediation
Detection
- Monitor access logs for requests to /plugin paths from unauthenticated or unexpected source IPs
- Alert on /plugin API calls originating outside the management network
- Review ShenYu configuration change history for plugin modifications without a corresponding authenticated session
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2022/01/25/15 | Mailing ListThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2022/01/25/5 | Mailing ListThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2022/01/26/2 | Mailing ListPatchThird Party Advisory |
| https://lists.apache.org/thread/dbrjnnlrf80dr0f92k5r2ysfvf1kr67y | Mailing ListVendor Advisory |
| http://www.openwall.com/lists/oss-security/2022/01/25/15 | Mailing ListThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2022/01/25/5 | Mailing ListThird Party Advisory |
| http://www.openwall.com/lists/oss-security/2022/01/26/2 | Mailing ListPatchThird Party Advisory |
| https://lists.apache.org/thread/dbrjnnlrf80dr0f92k5r2ysfvf1kr67y | Mailing ListVendor Advisory |
Track CVE-2022-23944 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-23944), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.