Miggo Logo

CVE-2021-37304: Insecure Permissions issue in jeecg-boot

7.5

CVSS Score
3.1

Basic Information

EPSS Score
0.97669%
Published
2/3/2023
Updated
2/10/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
org.jeecgframework.boot:jeecg-boot-basemaven<= 2.4.5

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The httptrace endpoint is the focal point of the vulnerability. The HttpTraceEndpoint class in Spring Boot Actuator is directly related to this endpoint. Thus, functions within this class are likely to be relevant. The exact method names (e.g., 'exchange') might vary based on the Spring Boot version and implementation details.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

*n Ins**ur* P*rmissions issu* in j****-*oot *.*.* *llows un*ut**nti**t** r*mot* *tt**k*rs to **in *s**l*t** privil*** *n* vi*w s*nsitiv* in*orm*tion vi* t** *ttptr*** int*r****.

Reasoning

T** *ttptr*** *n*point is t** *o**l point o* t** vuln*r**ility. T** `*ttpTr****n*point` *l*ss in Sprin* *oot **tu*tor is *ir**tly r*l*t** to t*is *n*point. T*us, *un*tions wit*in t*is *l*ss *r* lik*ly to ** r*l*v*nt. T** *x**t m*t*o* n*m*s (*.*., '*x