Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-37580 — Proof-of-concept exploit for Apache ShenYu Admin JWT authentication bypass (CVE-2021-37580). Includes a scanning script to detect vulnerable instances and retrieve admin credentials. | Kitploit
Tools/GitHubGitHub/rabbitsafe/cve-2021-37580
Authentication & AuthorizationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingAPI Security
GitHubrabbitsafe/cve-2021-37580

CVE-2021-37580

Proof-of-concept exploit for Apache ShenYu Admin JWT authentication bypass (CVE-2021-37580). Includes a scanning script to detect vulnerable instances and retrieve admin credentials.

View Repository
43624 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Apache ShenYu Admin has an authentication bypass vulnerability that allows attackers to bypass JSON Web Token (JWT) security authentication and directly access the system backend. Apache ShenYu is an extensible, high-performance, and reactive API gateway solution used in all microservice scenarios.

Apache ShenYu Admin has an authentication bypass vulnerability. The incorrect use of JWT in ShenyuAdminBootstrap allows attackers to bypass authentication, gaining direct access to the system backend.

CVE ID CVE-2021-37580

fofa:fid="uPGDN6V9UWnc+KJdy5wdkQ=="

Affected versions: Apache ShenYu 2.3.0 Apache ShenYu 2.4.0

Vulnerability Reproduction GET /dashboardUser Generate a JWT, add it to the header, and send the packet. image From the response packet, you can obtain the administrator account and password and log in to the system backend.

The scanning script CVE-2021-37580.py requires the pocsuite3 environment and jwt installation. Command: python3 -m pip install jwt image

Download Tool