Record summary

CVE-2021-37304 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 26, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

org.jeecgframework.boot:jeecg-boot-base

Browse Maven / org.jeecgframework.boot:jeecg-boot-base
GitHub AdvisoryThrough 2.4.5affected

Nuclei templates

1
ProjectDiscoveryHIGHJeecg Boot <= 2.4.5 - Information DisclosureCVSS 7.5

An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.

Impact

An attacker can exploit this vulnerability to gain sensitive information from the application.

Remediation

Upgrade Jeecg Boot to a version higher than 2.4.5 to mitigate the vulnerability.

WeaknessesCWE-732
Authorsritikchaddha
Template tagscve2021cvejeecgexposurevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:jeecg:jeecg:*:*:*:*:*:*:*:*
Shodan: title:"Jeecg-Boot"
Shodan: http.title:"jeecg-boot"
FOFA: title="JeecgBoot 企业级低代码平台"
FOFA: title="jeecg-boot"
FOFA: title="jeecgboot 企业级低代码平台"
Google: intitle:"jeecg-boot"

Source: ProjectDiscovery

References

3