Description
PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail.
Remediation
References
https://github.com/PowerJob/PowerJob/
https://github.com/PowerJob/PowerJob/issues/675
https://novysodope.github.io/2023/07/02/100/
Related Vulnerabilities
CVE-2019-9737 Vulnerability in maven package org.webjars.bowergithub.pandao:editor.md
CVE-2022-35948 Vulnerability in maven package org.webjars.npm:undici
CVE-2022-42003 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-37914 Vulnerability in maven package org.xwiki.platform:xwiki-platform-invitation-ui
CVE-2018-16487 Vulnerability in maven package org.fujion.webjars:lodash