Description
XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 report is about an intended and supported use case (running arbitrary Bash scripts on behalf of users).
Remediation
References
https://github.com/xuxueli/xxl-job/issues/2979
Related Vulnerabilities
CVE-2021-4040 Vulnerability in maven package org.apache.activemq:artemis-commons
CVE-2020-6429 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-28155 Vulnerability in npm package request
CVE-2021-27884 Vulnerability in npm package yapi-vendor
CVE-2022-41401 Vulnerability in maven package org.openrefine:main