Skip to content

[GHSA-25gv-mvm7-5h3h] Jeecg-boot vulnerable to SQL injection via /sys/user/putRecycleBin #5829

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Conversation

achibear
Copy link

Updates

  • Affected products

Comments
According to jeecgboot/JeecgBoot@51e2227, the fix version is 3.4.3last

@github-actions github-actions bot changed the base branch from main to achibear/advisory-improvement-5829 July 18, 2025 18:14
@shelbyc
Copy link
Contributor

shelbyc commented Jul 18, 2025

Hi @achibear, you're correct that jeecgboot/JeecgBoot@51e2227 is tagged with 3.4.3last. However, the currently listed Maven package (https://mvnrepository.com/artifact/org.jeecgframework.boot/jeecg-boot-common) and the package that I think is a better fit (https://mvnrepository.com/artifact/org.jeecgframework.boot/jeecg-module-system) don't have a version called 3.4.3last, and the earliest patched versions in those two Maven listings is 3.4.4. Indeed, the only listed version in https://mvnrepository.com/artifact/org.jeecgframework.boot/jeecg-module-system at all is 3.4.4.

I'm still accepting the PR because you showing me the fix commit jeecgboot/JeecgBoot@51e2227 made me notice that it's prudent to change the affected product from org.jeecgframework.boot:jeecg-boot-common to org.jeecgframework.boot:jeecg-module-system, but the lack of a 3.4.3last version in either package makes 3.4.4 the first patched version.

@advisory-database advisory-database bot merged commit 5ba4481 into achibear/advisory-improvement-5829 Jul 18, 2025
4 checks passed
@advisory-database
Copy link
Contributor

Hi @achibear! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants