1.45.0
5 years ago
5 months ago
Known vulnerabilities in the cn.dev33:sa-token-core package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Authentication Bypass via a crafted payload to the URL. An attacker can escalate privileges by sending a malicious payload. Note Exploiting this vulnerability is possible if using a vulnerable version of this package with SpringBoot version >= 2.3.1.RELEASE or Spring version >= 5.3.0. How to fix Authentication Bypass? Upgrade | [,1.37.0) |
Affected versions of this package are vulnerable to Improper Authentication when using Spring dynamic controllers, an attacker can bypass authentication by sending a specially crafted request. How to fix Improper Authentication? Upgrade | [,1.36.0) |