{"id":"GHSA-7wq4-89xx-g62j","summary":"Password exposure in ShenYu","details":"On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later.","aliases":["CVE-2022-23223"],"modified":"2024-02-16T05:24:49.082961Z","published":"2022-01-28T22:13:57Z","database_specific":{"nvd_published_at":"2022-01-25T13:15:00Z","cwe_ids":["CWE-522"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-01-26T22:42:18Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-23223"},{"type":"WEB","url":"https://github.com/apache/shenyu/pull/2357"},{"type":"WEB","url":"https://github.com/apache/shenyu/commit/0e826ceae97a1258cb15c73a3072118c920e8654"},{"type":"WEB","url":"https://github.com/apache/incubator-shenyu"},{"type":"WEB","url":"https://github.com/apache/incubator-shenyu/releases/tag/v2.4.2"},{"type":"WEB","url":"https://lists.apache.org/thread/q2gg6ny6lpkph7nkrvjzqdvqpm805v8s"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/01/25/7"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2022/01/26/4"}],"affected":[{"package":{"name":"org.apache.shenyu:shenyu-common","ecosystem":"Maven","purl":"pkg:maven/org.apache.shenyu/shenyu-common"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.4.0"},{"fixed":"2.4.2"}]}],"versions":["2.4.0","2.4.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-7wq4-89xx-g62j/GHSA-7wq4-89xx-g62j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}