Impact
A flaw in the AiragAppController release handler permits any authenticated user to publish or unpublish other users’ AI applications. By sending POST requests to /airag/app/release, an attacker can generate share tokens that expose applications to anonymous access or invalidate existing share links, effectively altering the availability and exposure of those applications.
Affected Systems
JeecgBoot products through version 3.9.5 are vulnerable. Any deployment using JeecgBoot 3.9.5 or earlier is affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, and the EPSS score is not available, meaning the likelihood of exploitation is unknown but the vulnerability does not require high privileges. Because the flaw requires only an authenticated user, an attacker with a valid account can achieve the exploit. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment