Description
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
Remediation
References
https://github.com/xuxueli/xxl-job/issues/2979
Related Vulnerabilities
CVE-2022-24898 Vulnerability in maven package org.xwiki.commons:xwiki-commons-xml
CVE-2018-6464 Vulnerability in npm package simditor
CVE-2022-25908 Vulnerability in npm package create-choo-electron
CVE-2020-28452 Vulnerability in maven package com.softwaremill.akka-http-session:core_2.13
CVE-2023-46589 Vulnerability in maven package org.apache.tomcat:tomcat-catalina