SaToken authentication bypass vulnerability
High severity
GitHub Reviewed
Published
Oct 25, 2023
to the GitHub Advisory Database
•
Updated Sep 11, 2024
Description
Published by the National Vulnerability Database
Oct 25, 2023
Published to the GitHub Advisory Database
Oct 25, 2023
Reviewed
Oct 27, 2023
Last updated
Sep 11, 2024
An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
References