CVE-2024-57438: Medium severity ruoyi ruoyi-cloud vulnerability
Published Jan 29, 2025
·Updated
Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.
Affected Software
2 affected components
maven/com.ruoyi:ruoyi<=4.8.0
Ruoyi Ruoyi=4.8.0
Event History
Jan 29, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
Affected Software
Advisory Published
via GitHub·03:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-57438?
CVE-2024-57438 is classified as a high-severity vulnerability due to its potential to enable privilege escalation.
2
How do I fix CVE-2024-57438?
To fix CVE-2024-57438, ensure that proper permission checks are enforced in the RuoYi application for role assignments.
3
Who is affected by CVE-2024-57438?
Users of RuoYi version 4.8.0 and earlier are affected by CVE-2024-57438 due to insecure permissions.
4
What type of vulnerability is CVE-2024-57438?
CVE-2024-57438 is a privilege escalation vulnerability that allows authenticated attackers to gain higher-level roles.
5
Is there a workaround for CVE-2024-57438?
A temporary workaround for CVE-2024-57438 is to manually audit and restrict role assignment permissions for authenticated users.