Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS05djY2LTkyMzktY3F2Ms4AA1Xm

Jeecg-boot SQL Injection vulnerability

SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via the Benchmark, PG_Sleep, DBMS_Lock.Sleep, Waitfor, DECODE, and DBMS_PIPE.RECEIVE_MESSAGE functions.

Permalink: https://github.com/advisories/GHSA-9v66-9239-cqv2
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS05djY2LTkyMzktY3F2Ms4AA1Xm
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 9 months ago
Updated: 6 months ago


CVSS Score: 5.5
CVSS vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Identifiers: GHSA-9v66-9239-cqv2, CVE-2023-38905
References: Repository: https://github.com/jeecgboot/jeecg-boot
Blast Radius: 1.0

Affected Packages

maven:org.jeecgframework.boot:jeecg-boot-parent
Affected Version Ranges: <= 3.5.0
No known fixed version