Description
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.
Remediation
References
https://github.com/Richard-Muzi/vulnerability/issues/1
Related Vulnerabilities
CVE-2021-43571 Vulnerability in npm package starkbank-ecdsa
CVE-2023-27096 Vulnerability in maven package cn.hippo4j:hippo4j-all
CVE-2022-24785 Vulnerability in maven package org.webjars.npm:moment
CVE-2020-23256 Vulnerability in npm package electerm
CVE-2020-2322 Vulnerability in maven package io.jenkins.plugins:chaos-monkey