CVE-2025-0704

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 24, 2025
CWE ID 404
CWE ID 400

Summary

CVE-2025-0704 is a recently disclosed vulnerability affecting the JoeyBling bootplus up to the version 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This issue lies within the qrCode function of the file src/main/java/io/github/controller/QrCodeController.java. An attacker can manipulate the argument w/h, leading to excessive resource consumption. This vulnerability is remotely exploitable, and the exploit has been made public. Given that this product uses a rolling release model for continuous delivery, no specific versions have been identified as affected or updated.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share