QID 996502
Date Published: 2024-01-04
QID 996502: Java (Maven) Security Update for org.jeecgframework.boot:jeecg-boot-common (GHSA-49jp-cghc-p5pj)
SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-49jp-cghc-p5pj for updates and patch information.
Vendor References
- GHSA-49jp-cghc-p5pj -
github.com/advisories/GHSA-49jp-cghc-p5pj
CVEs related to QID 996502
Software Advisories
| Advisory ID | Software | Component | Link |
|---|