Dromara Vulnerabilities and Affected Products
Vulnerabilities associated with open-capacity-platform.
Products
Clear product- hertzbeat7 vulnerabilities
- lamp-cloud6 vulnerabilities
- UJCMS5 vulnerabilities
- MaxKey4 vulnerabilities
- Sa-Token4 vulnerabilities
- J2eeFAST3 vulnerabilities
- RuoYi-Vue-Plus3 vulnerabilities
- HuTool2 vulnerabilities
- dataCompare1 vulnerability
- Northstar1 vulnerability
- open-capacity-platform1 vulnerability
- warm-flow1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-3928MEDIUM | Dromara open-capacity-platform auth-server heapdump information disclosureA vulnerability was found in Dromara open-capacity-platform 2.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /actuator/heapdump of the component auth-server. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261367. CWE-200Apr 17, 2024 | CVSS4.3v3.1 | EPSS0.527% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |