CVE-2020-19229: Jeesite

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an attacker could exploit the vulnerability to execute arbitrary commands via the rememberMe parameter.

Affected products

  • Jeesite Jeesite: version 1.2.7 only

Published 2022-04-05. Last modified 2026-06-17.