High
Apache ShenYu could allow a remote attacker to bypass security restrictions, caused by missing authentication on ShenYu Admin. By sending a specially-crafted request, an attacker could exploit this vulnerability to bypass access restrictions.
Apache ShenYu could allow a remote authenticated attacker to bypass security restrictions, caused by improper authentication. By sending a specially-crafted request, an attacker could exploit this vulnerability to access plugin api.
Apache ShenYu could allow a remote attacker to obtain sensitive information, caused by a flaw in the HTTP response. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to obtain sensitive information.
Apache Karaf could allow a remote attacker to traverse directories on the system, caused by a flaw in the karaf-maven-plugin. An attacker could send a specially-crafted URL request to view arbitrary folders on the system.
Apache ShenYu could allow a remote attacker to execute arbitrary code on the system, caused by Groovy Code Injection & SpEL Injection. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Apache Karaf could allow a remote attacker to execute arbitrary code on the system, caused by insecure java deserialization. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Apache
Upgrade to the latest version of Apache, available from the Apache Web site
Apache ShenYu:
Apache Karaf: