Description
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/2794
Related Vulnerabilities
CVE-2016-8609 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2019-17554 Vulnerability in maven package org.apache.olingo:odata-server-api
CVE-2021-40663 Vulnerability in npm package deep.assign
CVE-2021-22134 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2022-43429 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test