First published: Wed Oct 25 2023(Updated: )
An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/cn.dev33:sa-token-core | <1.37.0 | 1.37.0 |
All of | ||
Any of | ||
Vmware Spring Boot | >=2.3.1 | |
VMware Spring Framework | >=5.3.0 | |
Dromara Sa-token | <1.37.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue in Dromara SaToken is CVE-2023-44794.
CVE-2023-44794 has a severity level of 9.8 (Critical).
The vulnerability in Dromara SaToken allows a remote attacker to escalate privileges via a crafted payload to the URL.
Dromara SaToken version 1.36.0 and versions prior to 1.37.0 are affected by this vulnerability.
To remediate the vulnerability in Dromara SaToken, update to version 1.37.0 or later.