[MAVEN:GHSA-C352-X843-GGPQ] XXL-JOB vulnerable to Server-Side Request Forgery

Severity Moderate
Affected Packages 1
CVEs 1

xxl-job <= 2.4.0 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.

Package Affected Version
pkg:maven/com.xuxueli/xxl-job <= 2.4.0
ID
MAVEN:GHSA-C352-X843-GGPQ
Severity
moderate
URL
https://github.com/advisories/GHSA-c352-x843-ggpq
Published
2024-02-08T15:30:27
(7 months ago)
Modified
2024-02-08T18:42:14
(7 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.xuxueli/xxl-job com.xuxueli xxl-job <= 2.4.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...