Dromara Vulnerabilities and Affected Products
Vulnerabilities associated with Sa-Token.
Products
Clear product- hertzbeat7 vulnerabilities
- lamp-cloud6 vulnerabilities
- UJCMS5 vulnerabilities
- MaxKey4 vulnerabilities
- Sa-Token4 vulnerabilities
- J2eeFAST3 vulnerabilities
- RuoYi-Vue-Plus3 vulnerabilities
- HuTool2 vulnerabilities
- dataCompare1 vulnerability
- Northstar1 vulnerability
- open-capacity-platform1 vulnerability
- warm-flow1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Dromara Sa-Token SaSerializerTemplateForJdkUseBase64.java ObjectInputStream.readObject deserializationA vulnerability has been found in Dromara Sa-Token up to 1.44.0. This issue affects the function ObjectInputStream.readObject of the file SaSerializerTemplateForJdkUseBase64.java. Such manipulation leads to deserialization. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is assessed as difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way… | CVSS2.3v4.0 | EPSS0.223% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Dromara Sa-Token SaJdkSerializer.java ObjectInputStream.readObject deserializationA weakness has been identified in Dromara Sa-Token up to 1.44.0. This affects the function ObjectInputStream.readObject of the file SaJdkSerializer.java. Executing manipulation can lead to deserialization. The attack may be launched remotely. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS2.3v4.0 | EPSS0.275% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
SaToken authentication bypass vulnerabilityAn issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authentication bypass. | CVSS-v4.0 | EPSS0.797% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
SaToken privilege escalation vulnerabilityAn issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL. | CVSS-v4.0 | EPSS0.964% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |