Description
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.
Remediation
References
https://github.com/jeecgboot/jeecg-boot/issues/2794
Related Vulnerabilities
CVE-2021-39171 Vulnerability in npm package passport-saml
CVE-2023-22491 Vulnerability in npm package gatsby-transformer-remark
CVE-2017-16035 Vulnerability in npm package hubl-server
CVE-2023-25763 Vulnerability in maven package org.jenkins-ci.plugins:email-ext
CVE-2019-10302 Vulnerability in maven package org.jenkins-ci.plugins:jira-ext