[MAVEN:GHSA-V3C9-W6G2-HJG3] Cross-Site Request Forgery in XXL-Job

Severity High
Affected Packages 1
CVEs 1

A Cross-Site Request Forgery (CSRF) in XXL-Job v2.3.0 allows attackers to arbitrarily create administrator accounts via the component /gaia-job-admin/user/add.

Package Affected Version
pkg:maven/com.xuxueli/xxl-job <= 2.3.0
ID
MAVEN:GHSA-V3C9-W6G2-HJG3
Severity
high
URL
https://github.com/advisories/GHSA-v3c9-w6g2-hjg3
Published
2022-05-24T00:00:18
(2 years ago)
Modified
2023-01-27T05:02:32
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.xuxueli/xxl-job com.xuxueli xxl-job <= 2.3.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...