{"id":"CVE-2021-37304","details":"An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.","aliases":["GHSA-rwhw-6c6r-2823"],"modified":"2026-08-27T08:40:26.208727Z","published":"2023-02-03T18:15:11.770Z","references":[{"type":"ADVISORY","url":"https://github.com/jeecgboot/jeecg-boot/issues/2793"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jeecgboot/JeecgBoot","events":[{"introduced":"0"},{"last_affected":"8b3d83ae0b08e5a0cc6ae14ba5a9b0820e1cb5c0"}],"database_specific":{"cpe":"cpe:2.3:a:jeecg:jeecg:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"2.4.5"}],"source":"CPE_RANGE"}}],"versions":["v2.4.5","2.4.5","v2.4.3","v2.4.2","v2.4.1","2.4.1","2.4.0","v2.3.0","2.3.0","v2.3","v2.2.1","2.2.0","v2.1.4","v2.1.3","v2.1.1","v2.1.0","v2.0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-37304.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}