S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2021-37304 Scanner

CVE-2021-37304 scanner - Information Disclosure vulnerability in Jeecg Boot

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-37304
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Jeecg Boot is an advanced, enterprise-level low-code platform that enables rapid development and deployment of web and mobile applications. It is widely used by developers to create efficient, scalable applications with minimal coding effort. This platform's flexibility and comprehensive feature set make it a popular choice for businesses looking to streamline their application development processes. However, vulnerabilities within such a platform can pose significant security risks, potentially leading to unauthorized access and data leakage.

The vulnerability specifically exists because the httptrace actuator endpoint is improperly secured, permitting unauthenticated access. An attacker can exploit this by sending a simple HTTP GET request to the endpoint, which then returns sensitive information about the application's HTTP trace data. This data can include HTTP request and response details, headers, and potentially sensitive information transmitted during the session.

If exploited, this vulnerability can lead to significant information disclosure. Attackers may gain insights into the application's internal workings, user data, session tokens, and other sensitive information that could be leveraged for further attacks, such as session hijacking, privilege escalation, or targeted phishing campaigns.

By leveraging the comprehensive scanning capabilities of the S4E platform, users can identify and mitigate vulnerabilities like CVE-2021-37304 efficiently. Our platform offers detailed insights and recommendations to secure your digital assets against emerging threats, ensuring the confidentiality, integrity, and availability of your information and systems.

 

References

Solution Advice
  1. Immediately upgrade to Jeecg Boot version higher than 2.4.5 to address this vulnerability.
  2. Review and restrict access to sensitive endpoints, ensuring that only authenticated and authorized users can access administrative functions.
  3. Implement proper access controls and authentication mechanisms on all administrative and sensitive endpoints.
  4. Regularly audit your application's security posture to identify and remediate potential vulnerabilities promptly.
  5. Educate your development and security teams about best practices for securing web applications and the importance of regular security assessments.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.