
Proof-of-concept exploit for Apache ShenYu Admin JWT authentication bypass (CVE-2021-37580). Includes a scanning script to detect vulnerable instances and retrieve admin credentials.
Apache ShenYu Admin has an authentication bypass vulnerability that allows attackers to bypass JSON Web Token (JWT) security authentication and directly access the system backend. Apache ShenYu is an extensible, high-performance, and reactive API gateway solution used in all microservice scenarios.
Apache ShenYu Admin has an authentication bypass vulnerability. The incorrect use of JWT in ShenyuAdminBootstrap allows attackers to bypass authentication, gaining direct access to the system backend.
CVE ID CVE-2021-37580
fofa:fid="uPGDN6V9UWnc+KJdy5wdkQ=="
Affected versions: Apache ShenYu 2.3.0 Apache ShenYu 2.4.0
Vulnerability Reproduction
GET /dashboardUser
Generate a JWT, add it to the header, and send the packet.
From the response packet, you can obtain the administrator account and password and log in to the system backend.
The scanning script CVE-2021-37580.py requires the pocsuite3 environment and jwt installation. Command: python3 -m pip install jwt
