Description
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/2794
Related Vulnerabilities
CVE-2022-25349 Vulnerability in maven package org.webjars.npm:materialize-css
CVE-2022-2191 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2022-28820 Vulnerability in maven package com.adobe.acs:acs-aem-commons
CVE-2017-2638 Vulnerability in maven package org.infinispan:infinispan-compatibility-mode-it
CVE-2022-30973 Vulnerability in maven package org.apache.tika:tika