CVE-2024-40489
There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://gist.github.com/aqyoung/2fd6329ceb06b731a621356921f0d5f0, https://pan.baidu.com/s/14WOPXhRHoxr4FRKGme59ug?pwd=sktp, https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/40xxx/CVE-2024-40489.json, https://nvd.nist.gov/vuln/detail/CVE-2024-40489