PT-2024-17556 · Guangzhou Huayi Intelligent Technology · Jeewms

Dycc

·

Published

2024-12-08

·

Updated

2024-12-09

·

CVE-2024-12347

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Guangzhou Huayi Intelligent Technology Jeewms version 1.0.0
Description A critical issue affects the Druid Monitoring Interface component, specifically the file /jeewms war/webpage/system/druid/index.html, leading to improper authorization. The attack can be initiated remotely. The exploit has been disclosed publicly, and the vendor was contacted but did not respond.
Recommendations For version 1.0.0, as a temporary workaround, consider restricting access to the Druid Monitoring Interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2024-12347

Affected Products

Jeewms