Apache Shenyu is an extensible, high-performance and responsive API gateway solution applied to all micro service scenarios.
An authentication bypass vulnerability exists in Apache Shenyu admin. The improper use of JWT in Shenyu admin bootstrap allows an attacker to bypass authentication, and the attacker can directly enter the system background through this vulnerability.
git clone https://github.com/Osyanina/westone-CVE-2021-37580-scanner.git
cd westone-CVE-2021-37580-scanner
cmd CVE-2021-37580.exe
Apache ShenYu 2.3.0
Apache ShenYu 2.4.0