{"id":"CVE-2022-37435","summary":"Apache ShenYu Admin Improper Privilege Management","details":"Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3.","aliases":["GHSA-fjjw-82xw-vfc2"],"modified":"2026-08-27T03:30:33.852045336Z","published":"2022-09-01T14:00:14Z","database_specific":{"cna_assigner":"apache","cwe_ids":["CWE-732"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/37xxx/CVE-2022-37435.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"Apache ShenYu 2.4.2 and 2.4.3"},{"last_affected":"Apache ShenYu 2.4.2 and 2.4.3"}]}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread/ndblyxr2fdrvjtgbs1bogxgv2cgk7t28"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/37xxx/CVE-2022-37435.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-37435"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/shenyu","events":[{"introduced":"794a3be979fc8f08e22e40f3ce75644df9c74dad"},{"last_affected":"7f3878a40b5f43c75262d2dbe60edc06be94500d"}],"database_specific":{"source":"CPE_STRING","cpe":["cpe:2.3:a:apache:shenyu:2.4.2:*:*:*:*:*:*:*","cpe:2.3:a:apache:shenyu:2.4.3:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.4.2"},{"last_affected":"2.4.2"},{"introduced":"2.4.3"},{"last_affected":"2.4.3"}]}}],"versions":["2.4.2","2.4.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-37435.json"}}],"schema_version":"1.9.0"}