Description
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.
Remediation
References
https://github.com/Richard-Muzi/vulnerability/issues/1
Related Vulnerabilities
CVE-2022-0235 Vulnerability in npm package node-fetch
CVE-2022-35144 Vulnerability in npm package raneto
CVE-2023-44487 Vulnerability in maven package io.helidon.http:helidon-http-http2
CVE-2020-36188 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2019-8331 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap