CVE-2024-40489

Source
https://cve.org/CVERecord?id=CVE-2024-40489
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-40489.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-40489
Published
2026-04-01T00:00:00Z
Modified
2026-07-15T01:49:07.929380227Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/40xxx/CVE-2024-40489.json"
}
References

Affected packages

Git / github.com/jeecgboot/jeecgboot

Affected ranges

Type
GIT
Repo
https://github.com/jeecgboot/jeecgboot
Events
Database specific
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:jeecg:jeecg_boot:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.0"
        },
        {
            "last_affected": "3.5.3"
        }
    ]
}

Affected versions

v3.*
v3.0
v3.0.0
v3.1.0
v3.2.0
v3.4.0
v3.4.2
v3.4.3
v3.4.3last
v3.4.4
v3.4.4last
v3.5.0
v3.5.1
v3.5.1last
v3.5.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-40489.json"