First published: Tue Jan 25 2022(Updated: )
In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jeecg Jeecg Boot | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-46089 is critical with a score of 9.8 out of 10.
CVE-2021-46089 is a SQL injection vulnerability in JeecgBoot 3.0 that allows unauthorized access to the database with root privileges.
CVE-2021-46089 affects JeecgBoot 3.0 by enabling an attacker to execute arbitrary SQL queries and potentially operate the database as a root user.
Yes, a fix is available for CVE-2021-46089. It is recommended to update to the latest version of JeecgBoot to mitigate the vulnerability.
More information about CVE-2021-46089 can be found at the following reference: [link](https://github.com/jeecgboot/jeecg-boot/issues/3331).