Description
An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files in the server.
Remediation
References
https://gitee.com/y_project/RuoYi/commit/432d5ce1be2e9384a6230d7ccd8401eef5ce02b0
https://gitee.com/y_project/RuoYi/issues/I697Q5
Related Vulnerabilities
CVE-2021-23440 Vulnerability in npm package set-value
CVE-2018-20821 Vulnerability in npm package node-sass
CVE-2021-21351 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2022-25758 Vulnerability in npm package scss-tokenizer
CVE-2019-1003030 Vulnerability in maven package org.jenkins-ci.plugins.workflow:workflow-cps