Description
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/2794
Related Vulnerabilities
CVE-2018-1000420 Vulnerability in maven package org.jenkins-ci.plugins:mesos
CVE-2022-45868 Vulnerability in maven package com.h2database:h2
CVE-2021-21345 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2016-10583 Vulnerability in maven package org.webjars.npm:closure-util
CVE-2019-12086 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind