Vulnerability record · CVE-2024-7314 · published 2 August 2024
CVE-2024-7314: AJ-Report authentication bypass via ;swagger-ui path allows RCE
AAnji Plus · Report
anji-plus AJ-Report contains an authentication bypass where appending ";swagger-ui" to HTTP requests skips authentication. Because the bypass exposes functionality that leads to arbitrary Java execution, an unauthenticated remote attacker can run code on the server. Exploitation evidence was observed in the wild by Shadowserver on 2025-02-05.
Description
anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to HTTP requests to bypass authentication and execute arbitrary Java on the victim server. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-05 UTC.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with high EPSS and observed in-the-wild exploitation.
What it is
anji-plus AJ-Report contains an authentication bypass where appending ";swagger-ui" to HTTP requests skips authentication. Because the bypass exposes functionality that leads to arbitrary Java execution, an unauthenticated remote attacker can run code on the server. Exploitation evidence was observed in the wild by Shadowserver on 2025-02-05.
Impact
An attacker gains unauthenticated remote code execution on the victim server, giving full control of the application process and its data. This can lead to data theft, lateral movement, and full host compromise.
Attack surface
Reachable over the network via HTTP requests with a crafted ";swagger-ui" path suffix; no authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is 0.5175 (98.9th percentile) and multiple references are tagged Exploit, with in-the-wild exploitation evidence reported by Shadowserver.
What to do
- Apply the vendor patch or upgrade AJ-Report to a fixed release as soon as one is available.
- If no patch exists, restrict network access to AJ-Report to trusted management networks only.
- Block or reject requests containing ";swagger-ui" path segments at the reverse proxy or WAF.
- Disable or remove the Swagger UI endpoint if it is not required.
- Rotate credentials and secrets on any host suspected of compromise.
Detection
- Search web logs for requests containing ";swagger-ui" in the URI path.
- Alert on unexpected Java child processes or outbound connections from the AJ-Report server.
- Monitor for anomalous POST requests to AJ-Report endpoints from unauthenticated sources.
- Review host telemetry for new files or scheduled tasks created by the AJ-Report service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/vulhub/vulhub/tree/master/aj-report/CNVD-2024-15077 | ExploitThird Party Advisory |
| https://github.com/yuebusao/AJ-REPORT-EXPLOIT | Exploit |
| https://vulncheck.com/advisories/aj-report-swagger | Third Party Advisory |
| https://xz.aliyun.com/t/14460 | ExploitThird Party Advisory |
Track CVE-2024-7314 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-7314), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.