GHSA-fqp6-fw9g-xpxp

Source
https://github.com/advisories/GHSA-fqp6-fw9g-xpxp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-fqp6-fw9g-xpxp/GHSA-fqp6-fw9g-xpxp.json
Aliases
Published
2023-02-03T18:30:26Z
Modified
2023-11-08T04:06:18.020284Z
Details

An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.

References

Affected packages

Maven / org.jeecgframework.boot:jeecg-boot-base

Package

Name
org.jeecgframework.boot:jeecg-boot-base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Last affected
2.4.5