CVE-2023-43961: High severity dromara sa-token vulnerability
An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-43961?
CVE-2023-43961 is a vulnerability in Dromara SaToken version 1.3.50RC and earlier versions, which can be exploited to bypass authentication.
How can this vulnerability be exploited?
This vulnerability can be exploited by sending a specially crafted request to the affected application, which may lead to an authentication bypass.
What is the severity of CVE-2023-43961?
The severity of CVE-2023-43961 is moderate.
How can I fix CVE-2023-43961?
To fix CVE-2023-43961, upgrade to Dromara SaToken version 1.3.50RC or later, specifically version 1.36.0 or higher.
Where can I find more information about CVE-2023-43961?
You can find more information about CVE-2023-43961 on the official GitHub page of Dromara Sa-Token and the NIST National Vulnerability Database (NVD).