1.39.0
4 years ago
4 months ago
Known vulnerabilities in the cn.dev33:sa-token-core package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Authentication Bypass via a crafted payload to the URL. An attacker can escalate privileges by sending a malicious payload. Note Exploiting this vulnerability is possible if using a vulnerable version of this package with SpringBoot version >= 2.3.1.RELEASE or Spring version >= 5.3.0. How to fix Authentication Bypass? Upgrade | [,1.37.0) |