CVE-2025-4533: JeecgBoot Document Library Upload zip unzipFile resource consumption
A vulnerability classified as problematic was found in JeecgBoot up to 3.8.0. This vulnerability affects the function unzipFile of the file /jeecg-boot/airag/knowledge/doc/import/zip of the component Document Library Upload. The manipulation of the argument File leads to resource consumption. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4533?
CVE-2025-4533 is classified as a problematic vulnerability.
How do I fix CVE-2025-4533?
To fix CVE-2025-4533, you need to upgrade JeecgBoot to a version higher than 3.8.0.
What components are affected by CVE-2025-4533?
CVE-2025-4533 affects the Document Library Upload component in JeecgBoot.
What specific function is exploited in CVE-2025-4533?
The vulnerability in CVE-2025-4533 exploits the function unzipFile within the application.
Which versions of JeecgBoot are impacted by CVE-2025-4533?
CVE-2025-4533 affects JeecgBoot versions up to and including 3.8.0.