JeecgBoot是中国国炬(Jeecg)公司的一个适用于企业 Web 应用程序的 Java 低代码平台。 JeecgBoot 3.9.1及之前版本存在代码问题漏洞,该漏洞源于Cloud Instance Metadata Endpoint组件中FileDownloadUtils.download2DiskFromNet函数处理URL时存在服务端请求伪造漏洞,可能导致远程攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jeecgboot | The server processes these URLs | 3.9.0 |
affected |
3.9.1 |
affected | ||
3.9.2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jeecgboot | The server processes these URLs | 3.9.0 |
cpe:2.3:a:jeecgboot:the_server_processes_these_urls:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet