Description
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.
Remediation
References
https://github.com/Richard-Muzi/vulnerability/issues/1
Related Vulnerabilities
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-hadoop-dbcp-service
CVE-2019-16560 Vulnerability in maven package org.jenkins-ci.plugins:websphere-deployer
CVE-2020-7621 Vulnerability in npm package strong-nginx-controller
CVE-2022-39353 Vulnerability in npm package @xmldom/xmldom
CVE-2022-39368 Vulnerability in maven package org.eclipse.californium:scandium