Описание
Dromara hutool vulnerable to SQL Injection
SQL Inection vulnerability in Dromara hutool v5.8.11 allows attacker to execute arbitrary code via the aviator template engine.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-24163
- https://github.com/dromara/hutool/issues/3149
- https://github.com/google/osv.dev/issues/2195
- https://gitee.com/dromara/hutool/issues/I6AJWJ#note_15801868
- https://gitee.com/dromara/hutool/issues/I6AJWJ#note_20057806_link
- https://github.com/dromara/hutool/releases/tag/5.8.21
Пакеты
Наименование
cn.hutool:hutool-all
maven
Затронутые версииВерсия исправления
< 5.8.21
5.8.21
Связанные уязвимости
CVSS3: 9.8
nvd
около 3 лет назад
SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.