CVE-2021-37306: High severity jeecg vulnerability
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-37306?
CVE-2021-37306 is an insecure permissions issue in jeecg-boot 2.4.5 and earlier that allows remote attackers to gain escalated privilege and view sensitive information.
How can remote attackers exploit CVE-2021-37306?
Remote attackers can exploit CVE-2021-37306 by sending a specially crafted request to the API uri '/sys/user/checkOnlyUser?username=admin', which allows them to gain escalated privilege and view sensitive information.
What is the severity of CVE-2021-37306?
CVE-2021-37306 has a severity of high with a CVSS (Common Vulnerability Scoring System) score of 7.5.
Which version of jeecg-boot is affected by CVE-2021-37306?
jeecg-boot version 2.4.5 and earlier are affected by CVE-2021-37306.
Is there a fix available for CVE-2021-37306?
Yes, the fix for CVE-2021-37306 is available in newer versions of jeecg-boot. It is recommended to update to the latest version to mitigate the vulnerability.