CVE-2023-25753

CVSS V2 None CVSS V3 None
Description
There exists an SSRF (Server-Side Request Forgery) vulnerability located at the /sandbox/proxyGateway endpoint. This vulnerability allows us to manipulate arbitrary requests and retrieve corresponding responses by inputting any URL into the requestUrl parameter. Of particular concern is our ability to exert control over the HTTP method, cookies, IP address, and headers. This effectively grants us the capability to dispatch complete HTTP requests to hosts of our choosing. This issue affects Apache ShenYu: 2.5.1. Upgrade to Apache ShenYu 2.6.0 or apply patch  https://github.com/apache/shenyu/pull/4776  .
Overview
  • CVE ID
  • CVE-2023-25753
  • Assigner
  • apache
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-10-19T08:35:24.075Z
  • Last Modified Date
  • 2023-10-19T08:35:31.452Z
References
Reference URL Reference Tags
https://lists.apache.org/thread/chprswxvb22z35vnoxv9tt3zknsm977d vendor-advisory
History
Created Old Value New Value Data Type Notes
2024-06-25 18:00:13 Added to TrackCVE