java-aodeng/hope-boot

java-aodeng/hope-boot

Releases11
Frequency1 month 1 day
Last Release
Stars3.24K
🌱 一款现代化的脚手架项目

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL

Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET request.

9.8 CRITICAL

hope-boot 1.0.0 has a deserialization vulnerability that can cause Remote Code Execution (RCE).