Опубликовано: 29 янв. 2025
Источник: github
Github: Прошло ревью
CVSS4: 7.8
CVSS3: 7.2
Описание
RuoYi allowed unauthorized attackers to view the session ID of the admin in the system monitoring
RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted cookie.
Пакеты
Наименование
com.ruoyi:ruoyi
maven
Затронутые версииВерсия исправления
<= 4.8.0
Отсутствует
Связанные уязвимости
CVSS3: 7.2
nvd
около 1 года назад
RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted cookie.