GHSA-4f48-qpch-4ppx

Source
https://github.com/advisories/GHSA-4f48-qpch-4ppx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-4f48-qpch-4ppx/GHSA-4f48-qpch-4ppx.json
Aliases
Published
2023-02-03T18:30:27Z
Modified
2023-11-08T04:06:17.959654Z
Details

An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.

References

Affected packages

Maven / org.jeecgframework.boot:jeecg-boot-base

Package

Name
org.jeecgframework.boot:jeecg-boot-base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Last affected
2.4.5