Description
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.
Remediation
References
https://github.com/Richard-Muzi/vulnerability/issues/1
Related Vulnerabilities
CVE-2020-7733 Vulnerability in maven package org.webjars.npm:ua-parser-js
CVE-2019-10468 Vulnerability in maven package com.elasticbox.jenkins-ci.plugins:kubernetes-ci
CVE-2013-4002 Vulnerability in maven package xerces:xercesimpl
CVE-2018-16487 Vulnerability in npm package lodash.merge
CVE-2023-1108 Vulnerability in maven package io.undertow:undertow-core