CVE-2024-57438

Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ruoyi:ruoyi:4.8.0:*:*:*:*:*:*:*

History

14 May 2025, 18:26

Type Values Removed Values Added
First Time Ruoyi ruoyi
Ruoyi
CPE cpe:2.3:a:ruoyi:ruoyi:4.8.0:*:*:*:*:*:*:*
References () https://gitee.com/y_project/RuoYi - () https://gitee.com/y_project/RuoYi - Product
References () https://github.com/peccc/restful_vul/blob/main/ruoyi_insecure_role_assignments/ruoyi_insecure_role_assignments.md - () https://github.com/peccc/restful_vul/blob/main/ruoyi_insecure_role_assignments/ruoyi_insecure_role_assignments.md - Exploit, Third Party Advisory
References () https://github.com/yangzongzhuan/RuoYi - () https://github.com/yangzongzhuan/RuoYi - Product
References () https://ruoyi.vip/ - () https://ruoyi.vip/ - Product

06 Feb 2025, 16:15

Type Values Removed Values Added
CWE CWE-863
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
Summary
  • (es) Los permisos inseguros en RuoYi v4.8.0 permiten a atacantes autenticados escalar privilegios al asignarse roles de nivel superior.

29 Jan 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-29 15:15

Updated : 2025-05-14 18:26


NVD link : CVE-2024-57438

Mitre link : CVE-2024-57438

CVE.ORG link : CVE-2024-57438


JSON object : View

Products Affected

ruoyi

  • ruoyi
CWE
CWE-863

Incorrect Authorization