Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwrp-6c28-gjv2

Опубликовано: 14 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.3

Описание

A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template. The manipulation leads to deserialization. The attack may be launched remotely. The vendor response to the GitHub issue report is: "Modified, next version updated".

A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template. The manipulation leads to deserialization. The attack may be launched remotely. The vendor response to the GitHub issue report is: "Modified, next version updated".

EPSS

Процентиль: 20%
0.00063
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-20
CWE-502

Связанные уязвимости

CVSS3: 6.3
nvd
6 месяцев назад

A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template. The manipulation leads to deserialization. The attack may be launched remotely. The vendor response to the GitHub issue report is: "Modified, next version updated".

EPSS

Процентиль: 20%
0.00063
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-20
CWE-502