logo

CVE-2023-1784 org.jeecgframework.boot:jeecg-boot-parent

Package

Manager: maven
Name: org.jeecgframework.boot:jeecg-boot-parent
Vulnerable Version: >=0 <=3.5.0

Severity

Level: Critical

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.00098 pctl0.27941

Details

jeecg-boot vulnerable to improper authentication A vulnerability was found in jeecg-boot 3.5.0 that affects some unknown processing of the component API Documentation. The manipulation leads to improper authentication because the software does not prove or insufficiently proves that an identity claim is correct when an actor claims to have a given identity. The attack may be initiated remotely and the exploit has been disclosed to the public and may be used.

Metadata

Created: 2023-03-31T21:30:37Z
Modified: 2023-04-07T21:33:30Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-6rfv-h5v8-cj7g/GHSA-6rfv-h5v8-cj7g.json
CWE IDs: ["CWE-287"]
Alternative ID: GHSA-6rfv-h5v8-cj7g
Finding: F006
Auto approve: 1