CVE-2023-41578
Java vulnerability analysis and mitigation

Overview

Jeecg boot up to version 3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection. The vulnerability was assigned CVE-2023-41578 and was disclosed on September 8, 2023. The vulnerability affects the Jeecg boot application up to version 3.5.3 (NVD).

Technical details

The vulnerability exists in the /testConnection route where a MySQL connection can be constructed to cause arbitrary file reading. The application has some protection during the parsing process for MySQL connections, specifically around the 'allowLoadLocalInfile' parameter, but this can be bypassed. The vulnerability has been assigned a CVSS v3.1 base score of 7.5 HIGH (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) (NVD, GitHub Issue).

Impact

The vulnerability allows remote attackers to read arbitrary files on the affected system. This could lead to exposure of sensitive information and potential system compromise through information disclosure (NVD).

Mitigation and workarounds

Organizations should upgrade to a version newer than 3.5.3 of Jeecg boot. If immediate upgrading is not possible, organizations should implement strict access controls to the /testConnection endpoint (NVD).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-55749HIGH8.7
  • JavaJava
  • org.xwiki.platform:xwiki-platform-tool-jetty-resources
NoYesDec 01, 2025
CVE-2025-13806MEDIUM6.9
  • JavaJava
  • org.nutz:nutzboot-parent
NoNoDec 01, 2025
CVE-2025-13805MEDIUM6.3
  • JavaJava
  • org.nutz:nutzboot-parent
NoNoDec 01, 2025
CVE-2025-13804MEDIUM5.3
  • JavaJava
  • org.nutz:nutzboot-parent
NoNoDec 01, 2025
CVE-2025-66372LOW2.8
  • JavaJava
  • org.mustangproject:library
NoYesNov 28, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management