{"id":"GHSA-v3v9-3jf4-5pxx","summary":"Jeecg P3 Biz Chat allows remote attackers to read arbitrary files","details":"Jeecg P3 Biz Chat 1.0.5 allows remote attackers to read arbitrary files through specific parameters.","aliases":["CVE-2023-33510"],"modified":"2023-11-08T04:12:40.919605Z","published":"2023-06-07T21:30:18Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-06-09T22:54:03Z","nvd_published_at":"2023-06-07T20:15:09Z","cwe_ids":["CWE-668"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-33510"},{"type":"WEB","url":"https://carl1l.github.io/2023/05/08/jeecg-p3-biz-chat-1-0-5-jar-has-arbitrary-file-read-vulnerability"}],"affected":[{"package":{"name":"org.jeecgframework.p3:jeecg-p3-biz-chat","ecosystem":"Maven","purl":"pkg:maven/org.jeecgframework.p3/jeecg-p3-biz-chat"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.0.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-v3v9-3jf4-5pxx/GHSA-v3v9-3jf4-5pxx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}