CVE-2023-34603: SQL Injection
JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryFilterTableDictInfo in method org.jeecg.modules.api.controller.SystemApiController.
Other sources
JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryFilterTableDictInfo at org.jeecg.modules.api.controller.SystemApiController.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.jeecgframework.boot:jeecg-boot-parentto a version that resolves this vulnerability.Fixed in 3.5.1
Event History
Frequently Asked Questions
What is the vulnerability ID of JeecgBoot?
The vulnerability ID of JeecgBoot is CVE-2023-34603.
What is the severity level of CVE-2023-34603?
The severity level of CVE-2023-34603 is high (7.5).
What is the affected version of JeecgBoot?
JeecgBoot up to version 3.5.1 is affected by CVE-2023-34603.
What is the description of CVE-2023-34603?
CVE-2023-34603 is a SQL injection vulnerability in JeecgBoot via the component queryFilterTableDictInfo at org.jeecg.modules.api.controller.SystemApiController.
Is there a fix available for CVE-2023-34603?
No fix is currently available for CVE-2023-34603. It is recommended to update to a patched version when it becomes available.