Description
An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files in the server.
Remediation
References
https://gitee.com/y_project/RuoYi/commit/432d5ce1be2e9384a6230d7ccd8401eef5ce02b0
https://gitee.com/y_project/RuoYi/issues/I697Q5
Related Vulnerabilities
CVE-2017-3200 Vulnerability in maven package org.graniteds:granite-generator
CVE-2020-21122 Vulnerability in maven package com.bstek.ureport:ureport2-console
CVE-2018-3721 Vulnerability in maven package org.webjars.bower:lodash
CVE-2019-18213 Vulnerability in maven package org.lsp4xml:org.eclipse.lsp4xml.extensions.web
CVE-2022-39366 Vulnerability in maven package io.acryl:datahub-client