CVE-2023-25753 - CVE House
Back to Database
Status published Unknown CVE-2023-25753

Server-Side Request Forgery in Apache ShenYu

Vulnerability Description

There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manipulate arbitrary requests and retrieve corresponding responses by inputting any URL into the requestUrl parameter. Of particular concern is our ability to exert control over the HTTP method, cookies, IP address, and headers. This effectively grants us the capability to dispatch complete HTTP requests to hosts of our choosing. This issue affects Apache ShenYu: 2.5.1. Upgrade to Apache ShenYu 2.6.0 or apply patch  https://github.com/apache/shenyu/pull/4776  .

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-25753

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • by3

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache ShenYu
Vulnerable Versions:
0

Timeline

Official Publish: October 19th, 2023
Last Modified: September 12th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)