CVE-2022-45207: Jeecg-boot vulnerable to SQL injection via updateNullByEmptyString
(updated )
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
References
- github.com/advisories/GHSA-4j2x-v3mr-467m
- github.com/jeecgboot/jeecg-boot
- github.com/jeecgboot/jeecg-boot/commit/8632a835c23f558dfee3584d7658cc6a13ccec6f
- github.com/jeecgboot/jeecg-boot/commit/958cf01649e67c79887c21f9c0ada42b552b7ee3
- github.com/jeecgboot/jeecg-boot/issues/4127
- nvd.nist.gov/vuln/detail/CVE-2022-45207
Code Behaviors & Features
Detect and mitigate CVE-2022-45207 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →