Description
xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3333
Related Vulnerabilities
CVE-2023-6134 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2020-9447 Vulnerability in maven package com.googlecode.gwtupload:gwtupload-samples
CVE-2023-38509 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livetable-ui
CVE-2019-15603 Vulnerability in npm package seeftl
CVE-2020-11023 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery