-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| cn.hippo4j:hippo4j-all | maven | <= 1.4.3 |
The GitHub issue #1059 explicitly identifies the deletePool method in ThreadPoolController as having missing authentication checks. The vulnerability allows privilege escalation by letting low-privileged users execute destructive operations (thread pool deletion) through an unprotected endpoint. The CWE-269 mapping confirms this is an improper privilege management issue where access controls are missing on a sensitive operation.
Ongoing coverage of React2Shell