VulnerabilityAnalyzed
CVE-2024-40489
There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests.
CRITICAL 9.8EPSS 0.52%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.52% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- jeecg/jeecg boot
- Source
- cve@mitre.org
References
- https://gist.github.com/aqyoung/2fd6329ceb06b731a621356921f0d5f0Third Party Advisory
- https://pan.baidu.com/s/14WOPXhRHoxr4FRKGme59ug?pwd=sktpPermissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.