Description
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/2794
Related Vulnerabilities
CVE-2017-5638 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2016-1000342 Vulnerability in maven package org.bouncycastle:bcprov-jdk15on
CVE-2021-3803 Vulnerability in npm package nth-check
CVE-2022-29577 Vulnerability in maven package org.owasp.antisamy:antisamy
CVE-2019-10405 Vulnerability in maven package org.jenkins-ci.main:jenkins-core