CVE-2021-28411: Critical severity ruoyi ruoyi-cloud vulnerability
Published Aug 11, 2023
·Updated
An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4.0, allows remote attackers to escalate privileges.
Affected Software
1 affected component
Ruoyi Ruoyi=3.4.0
Event History
Aug 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2021-28411?
CVE-2021-28411 is a vulnerability found in the CookieRememberMeManager class in RuoYi version 3.4.0, which allows remote attackers to escalate privileges.
2
How severe is CVE-2021-28411?
CVE-2021-28411 is considered critical, with a severity score of 9.8.
3
What software versions are affected by CVE-2021-28411?
CVE-2021-28411 affects RuoYi version 3.4.0.
4
How can I fix CVE-2021-28411?
To fix CVE-2021-28411, it is recommended to update to a patched version of RuoYi.
5
Where can I find more information about CVE-2021-28411?
More information about CVE-2021-28411 can be found at the following link: https://github.com/lerry903/RuoYi/issues/20