First published: Fri Sep 08 2023(Updated: )
Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jeecgframework.boot:jeecg-boot-parent | <=3.5.3 | |
Jeecg Jeecg Boot | <=3.5.3 | |
<=3.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41578 is an arbitrary file read vulnerability in Jeecg boot up to v3.5.3 via the `/testConnection` interface.
CVE-2023-41578 has a severity rating of 7.5 (high).
CVE-2023-41578 affects Jeecg boot up to v3.5.3.
To fix CVE-2023-41578, update your Jeecg boot version to a version higher than or equal to 3.5.3.
You can find more information about CVE-2023-41578 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-41578), [GitHub Issue](https://github.com/Snakinya/Bugs/issues/1), [GitHub Advisory](https://github.com/advisories/GHSA-pm8v-ppx7-8hr4).