mybatis-plus >= 3.5.3.1 but got CVE-2023-25330 #5986
Closed
nicliuqi
started this conversation in
False Detection
Replies: 1 comment
-
Duplicate of #5985 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
IDs
CVE-2023-25330
Description
The content of the pom.xml is
After scan the pom.xml, the report is unexpected. There seems to report a CRITICAL vulnerability which number is CVE-2023-25330. The description of it says "A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands via the tenant ID valuer."
But the 3.5.3.1 version of mybatis-plus should not be matched.
Reproduction Steps
Target
Filesystem
Scanner
Vulnerability
Target OS
Ubuntu 20.04
Debug Output
Version
Checklist
-f json
that shows data sources and confirmed that the security advisory in data sources was correctBeta Was this translation helpful? Give feedback.
All reactions