CVE-2023-44794: Critical severity vmware spring boot tools vulnerability
Published Oct 25, 2023
·Updated
An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.
Affected Software
4 affected componentsFixes available
maven/cn.dev33:sa-token-core<1.37.0
1.37.0
All of the following
Any of the following
VMware Spring Boot>=2.3.1
VMware Spring Framework>=5.3.0
Dromara Sa-token<1.37.0
Event History
Oct 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
06:32 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue in Dromara SaToken?
The vulnerability ID for this issue in Dromara SaToken is CVE-2023-44794.
2
What is the severity of CVE-2023-44794?
CVE-2023-44794 has a severity level of 9.8 (Critical).
3
How does the vulnerability in Dromara SaToken allow privilege escalation?
The vulnerability in Dromara SaToken allows a remote attacker to escalate privileges via a crafted payload to the URL.
4
Which version of Dromara SaToken is affected by this vulnerability?
Dromara SaToken version 1.36.0 and versions prior to 1.37.0 are affected by this vulnerability.
5
How can I remediate the vulnerability in Dromara SaToken?
To remediate the vulnerability in Dromara SaToken, update to version 1.37.0 or later.