CVE-2025-10319: JeecgBoot Tenant Log Export exportLog improper authorization
A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog of the component Tenant Log Export. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10319?
CVE-2025-10319 has been classified as a medium severity vulnerability due to improper authorization in the Tenant Log Export functionality.
Which versions of JeecgBoot are affected by CVE-2025-10319?
CVE-2025-10319 affects JeecgBoot versions up to and including 3.8.2.
How do I fix CVE-2025-10319?
To fix CVE-2025-10319, upgrade JeecgBoot to a version that is higher than 3.8.2 where the vulnerability is patched.
Can CVE-2025-10319 be exploited remotely?
Yes, the vulnerability described in CVE-2025-10319 can be exploited remotely.
What impact does CVE-2025-10319 have on systems?
CVE-2025-10319 can lead to unauthorized access and manipulation of tenant logs, potentially compromising sensitive data.