Description
Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection.
Remediation
References
https://github.com/Snakinya/Bugs/issues/1
Related Vulnerabilities
CVE-2022-29078 Vulnerability in maven package org.webjars.npm:ejs
CVE-2022-22881 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base
CVE-2019-13236 Vulnerability in maven package org.opencms:opencms-core
CVE-2020-7608 Vulnerability in npm package yargs-parser
CVE-2021-23356 Vulnerability in npm package kill-process-by-name