CVE-2023-24163

SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hutool:hutool:*:*:*:*:*:*:*:*

History

21 May 2024, 17:23

Type Values Removed Values Added
CPE cpe:2.3:a:hutool:hutool:5.8.11:*:*:*:*:*:*:* cpe:2.3:a:hutool:hutool:*:*:*:*:*:*:*:*
References () https://gitee.com/dromara/hutool/issues/I6AJWJ#note_20057806_link - () https://gitee.com/dromara/hutool/issues/I6AJWJ#note_20057806_link - Issue Tracking
References () https://github.com/dromara/hutool/issues/3149 - () https://github.com/dromara/hutool/issues/3149 - Issue Tracking
References () https://github.com/dromara/hutool/releases/tag/5.8.21 - () https://github.com/dromara/hutool/releases/tag/5.8.21 - Release Notes
References () https://github.com/google/osv.dev/issues/2195 - () https://github.com/google/osv.dev/issues/2195 - Issue Tracking

15 May 2024, 16:15

Type Values Removed Values Added
Summary (en) SQL Inection vulnerability in Dromara hutool v5.8.11 allows attacker to execute arbitrary code via the aviator template engine. (en) SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.
References
  • () https://gitee.com/dromara/hutool/issues/I6AJWJ#note_20057806_link -
  • () https://github.com/dromara/hutool/issues/3149 -
  • () https://github.com/dromara/hutool/releases/tag/5.8.21 -
  • () https://github.com/google/osv.dev/issues/2195 -

Information

Published : 2023-01-31 16:15

Updated : 2024-05-21 17:23


NVD link : CVE-2023-24163

Mitre link : CVE-2023-24163

CVE.ORG link : CVE-2023-24163


JSON object : View

Products Affected

hutool

  • hutool
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')