CVE-2022-23944: Missing authentication in ShenYu

Severity: Critical

CVSS Score: 9.1

User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1.