High severity7.5NVD Advisory· Published Feb 3, 2023· Updated Jun 17, 2026
CVE-2021-37306
CVE-2021-37306
Description
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jeecgframework.boot:jeecg-boot-baseMaven | <= 2.4.5 | — |
Affected products
3- jeecg-boot/jeecg-bootdescription
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-fqp6-fw9g-xpxpghsaADVISORY
- github.com/jeecgboot/jeecg-boot/issues/2794nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-37306ghsaADVISORY
News mentions
0No linked articles in our index yet.