GHSA-h855-6hph-v363

Source
https://github.com/advisories/GHSA-h855-6hph-v363
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-h855-6hph-v363/GHSA-h855-6hph-v363.json
Aliases
Published
2023-03-27T15:30:17Z
Modified
2023-11-08T04:12:03.442757Z
Details

Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker to obtain sensitive information via the ConfigVerifyController function of the Tenant Management module.

References

Affected packages

Maven / cn.hippo4j:hippo4j-all

Package

Name
cn.hippo4j:hippo4j-all

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Last affected
1.4.3

Affected versions

0.*

0.0.1
0.9.0

1.*

1.0.0-alpha
1.0.0-alpha2
1.0.0-alpha3
1.0.0-beta
1.0.0-beta.2
1.0.0-beta.3
1.0.0-beta.4
1.0.0-beta.5
1.0.0-beta.6
1.0.0-beta.7
1.0.0-RC1
1.0.0-RC2
1.0.0-RC3
1.0.0
1.1.0-alpha
1.1.0-alpha.2
1.1.0-beta
1.1.0-beta.2
1.1.0-beta.3
1.1.0-beta.4
1.1.0-RC1
1.1.0
1.2.0-alpha
1.2.0-RC2
1.2.0-RC3
1.2.0-RC4
1.2.0-RC5
1.2.0-RC6
1.2.0
1.2.1
1.3.0-beta
1.3.0-beta.2
1.3.0.alpha
1.3.0
1.3.1
1.4.0-alpha
1.4.0-RC
1.4.0
1.4.1
1.4.2-alpha
1.4.2-alpha.2
1.4.2
1.4.3