CVE-2021-37304: High severity jeecg vulnerability
Published Feb 3, 2023
·Updated
An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.
Affected Software
1 affected component
Jeecg jeecg<=2.4.5
Event History
Feb 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-37304.
2
What is the title of this vulnerability?
The title of this vulnerability is 'An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.'
3
What is the severity of CVE-2021-37304?
The severity of CVE-2021-37304 is high, with a severity value of 7.5.
4
What software versions are affected by this vulnerability?
jeecg-boot 2.4.5 is affected by this vulnerability.
5
How can an attacker exploit this vulnerability?
An unauthenticated remote attacker can exploit this vulnerability by gaining escalated privilege and viewing sensitive information via the httptrace interface.