Description
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/2794
Related Vulnerabilities
CVE-2018-25031 Vulnerability in npm package swagger-ui
CVE-2020-2202 Vulnerability in maven package org.jenkins-ci.plugins:fortify-on-demand-uploader
CVE-2021-23358 Vulnerability in maven package org.webjars.npm:underscore
CVE-2022-41404 Vulnerability in maven package org.ini4j:ini4j
CVE-2021-44832 Vulnerability in maven package org.apache.logging.log4j:log4j-core