Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an attacker could exploit the vulnerability to execute arbitrary commands via the rememberMe parameter.
More Stories
USN-7459-1: Linux kernel (Intel IoTG) vulnerabilities
Jann Horn discovered that the watch_queue event notification subsystem in the Linux kernel contained an out-of-bounds write vulnerability. A local...
USN-7458-1: Linux kernel (IBM) vulnerabilities
Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker...
rust-hickory-proto-0.24.4-1.fc42
FEDORA-2025-99f0d93d68 Packages in this update: rust-hickory-proto-0.24.4-1.fc42 Update description: Update to version 0.24.4. Also contains fixes for RUSTSEC-2025-0006. Read More
rust-hickory-proto-0.24.4-1.fc40
FEDORA-2025-5e5b0cc812 Packages in this update: rust-hickory-proto-0.24.4-1.fc40 Update description: Update to version 0.24.4. Also contains fixes for RUSTSEC-2025-0006. Read More
rust-hickory-proto-0.24.4-1.fc41
FEDORA-2025-def79f4594 Packages in this update: rust-hickory-proto-0.24.4-1.fc41 Update description: Update to version 0.24.4. Also contains fixes for RUSTSEC-2025-0006. Read More
rust-hickory-proto-0.24.4-1.el9
FEDORA-EPEL-2025-fac458e143 Packages in this update: rust-hickory-proto-0.24.4-1.el9 Update description: Update to version 0.24.4. Also contains fixes for RUSTSEC-2025-0006. Read More