Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS0yM3hmLTU1MzUtNjJ2Nc4AAyeJ

jeecg-boot vulnerable to SQL injection

jeecg-boot 3.5.0 is vulnerable to SQL injection from functionality of the file SysDictMapper.java of the component Sleep Command Handler. The attack can be launched remotely and the exploit has been disclosed to the public and may be used.

Permalink: https://github.com/advisories/GHSA-23xf-5535-62v5
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yM3hmLTU1MzUtNjJ2Nc4AAyeJ
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: about 1 year ago
Updated: about 1 year ago


CVSS Score: 9.8
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-23xf-5535-62v5, CVE-2023-1741
References: Repository: https://github.com/private-null/report
Blast Radius: 1.0

Affected Packages

maven:org.jeecgframework.boot:jeecg-boot-parent
Affected Version Ranges: <= 3.5.0
No known fixed version