Description
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/2794
Related Vulnerabilities
CVE-2022-24718 Vulnerability in npm package @finastra/ssr-pages
CVE-2022-34115 Vulnerability in maven package io.dataease:dataease-plugin-common
CVE-2022-27820 Vulnerability in maven package org.zaproxy:zap
CVE-2019-15599 Vulnerability in maven package org.webjars.npm:tree-kill
CVE-2016-0760 Vulnerability in maven package org.apache.sentry:sentry-binding-hive