[MAVEN:GHSA-JF2F-HVXX-4RQX] jeecg-boot unrestricted file upload vulnerability

Severity Moderate
Affected Packages 1
CVEs 1

jeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.

Package Affected Version
pkg:maven/org.jeecgframework.boot/jeecg-boot-parent <= 3.5.0
ID
MAVEN:GHSA-JF2F-HVXX-4RQX
Severity
moderate
URL
https://github.com/advisories/GHSA-jf2f-hvxx-4rqx
Published
2023-06-16T18:30:33
(15 months ago)
Modified
2023-11-07T05:02:51
(10 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jeecgframework.boot/jeecg-boot-parent org.jeecgframework.boot jeecg-boot-parent <= 3.5.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...