CVE-2021-37304
Insecure Permissions issue in jeecg-boot
Record summary
CVE-2021-37304 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 26, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
org.jeecgframework.boot:jeecg-boot-baseBrowse Maven / org.jeecgframework.boot:jeecg-boot-base | GitHub Advisory | Through 2.4.5 | affected |
Nuclei templates
1ProjectDiscoveryHIGHJeecg Boot <= 2.4.5 - Information DisclosureCVSS 7.5
An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.
Impact
An attacker can exploit this vulnerability to gain sensitive information from the application.
Remediation
Upgrade Jeecg Boot to a version higher than 2.4.5 to mitigate the vulnerability.
Source: ProjectDiscovery