important · RCE — JimuReport
JimuReport 2.5.1’s no-login export path turns a forged fixed-key signature into server-side command execution.
Affects
JimuReport, a Java/Spring Boot web-based reporting and dashboard server.
A caller needs a valid report identifier but no account, then uses the hard-coded signing secret to reach Aviator evaluation and escape its sandbox.
Detail and 2 sources
No patch is available for the documented JimuReport path.