chillzhuang/SpringBlade

chillzhuang/SpringBlade

Releases26
Frequency2 months 2 weeks
Last Release
Stars6.92K
SpringBlade 是一个由商业级项目升级优化而来的微服务架构,采用Spring Boot 4 、Spring Cloud 2025、Java 21 等核心技术构建,完全遵循阿里巴巴编码规范。提供基于React和Vue的两个前端框架用于快速搭建企业级的SaaS多租户微服务平台。

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into the content parameter.

8.8 HIGH

An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload.

5 MEDIUM

A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows authenticated attackers to scan internal resources via a crafted GET request.

= 4.5.09.9 CRITICAL

Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data.

= 4.5.09.9 CRITICAL

Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.

<= 3.6.05.3 MEDIUM

SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs

= *, <= 2.7.19.8 CRITICAL7.5 HIGH

The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.