Headline
GHSA-6w89-c65w-jx2c: Jeecg-boot is vulnerable to SQL injection
Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData
. A patch was released in commit 0fc374.
Package
maven org.jeecgframework.boot:jeecg-boot-base-core (Maven)
Affected versions
<= 3.4.4
maven org.jeecgframework.boot:jeecg-module-system (Maven)
Related news
CVE-2022-47105: jeecg-boot3.4.4 存在sql注入漏洞 · Issue #4393 · jeecgboot/jeecg-boot
Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.