Description
XXL-JOB all versions as of 11 July 2022 are vulnerable to Insecure Permissions resulting in the ability to execute admin function with low Privilege account.
Remediation
References
https://github.com/Richard-Muzi/vulnerability/issues/1
Related Vulnerabilities
CVE-2021-23484 Vulnerability in npm package zip-local
CVE-2019-10907 Vulnerability in maven package org.airsonic.player:airsonic-main
CVE-2023-40037 Vulnerability in maven package org.apache.nifi:nifi-dbcp-service-api
CVE-2018-20677 Vulnerability in maven package org.webjars.bowergithub.jasny:bootstrap
CVE-2023-43494 Vulnerability in maven package org.jenkins-ci.main:jenkins-core