CVE-2023-49442: Critical severity jeecg vulnerability
Published Jan 3, 2024
·Updated
Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.
Affected Software
1 affected component
Jeecg jeecg<=4.0
Event History
Jan 3, 2024
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49442?
CVE-2023-49442 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2023-49442?
To mitigate CVE-2023-49442, update to JEECG version 4.1 or later, which resolves this deserialization issue.
3
What are the potential impacts of CVE-2023-49442?
The potential impacts of CVE-2023-49442 include unauthorized access, data manipulation, and system compromise.
4
Who is affected by CVE-2023-49442?
CVE-2023-49442 affects all users of JEECG version 4.0 and earlier.
5
What is the nature of the attack for CVE-2023-49442?
CVE-2023-49442 allows attackers to exploit deserialization flaws through crafted POST requests to execute arbitrary code.