Description
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/2794
Related Vulnerabilities
CVE-2019-17592 Vulnerability in npm package csv-parse
CVE-2021-3856 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2016-10735 Vulnerability in maven package ru.taskurotta:bootstrap
CVE-2020-2201 Vulnerability in maven package org.jenkins-ci.plugins:sonargraph-integration
CVE-2020-2211 Vulnerability in maven package com.elasticbox.jenkins-ci.plugins:kubernetes-ci