-
-
Notifications
You must be signed in to change notification settings - Fork 2.2k
Open
Description
Summary
Druid credential is hardcoded, when user uses the default credential or it is leaked, which can lead to allow attacker gather sensitive operation information.
Details
- ruoyi-admin/src/main/resources/application-druid.yml
url-pattern: /druid/*
# 控制台管理用户名和密码
login-username: ruoyi
login-password: 123456
POC
http://127.0.0.1:8090/druid/websession.html
Impact
when user uses the default credential or it is leaked, which can lead to allow attacker gather sensitive operation information.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels