SpringBlade Default SIGN_KRY (CVE-2021-44910)

SpringBlade is a comprehensive project that coexists with the SpringCloud distributed microservice architecture and the SpringBoot monolithic microservice architecture upgraded and optimized from commercial-grade projects. The SpringBlade framework has a default SIGN_KEY, and attackers can exploit the vulnerability to obtain sensitive information such as user account password logs.

FOFA query rule: body="saber/iconfont.css" || body="Saber 将不能正常工作" || title="Sword Admin" || body="We're sorry but avue-data doesn't work"

Demo

SpringBlade_Default_SIGN_KRY_CVE_2021_44910