Description
xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3333
Related Vulnerabilities
CVE-2020-11991 Vulnerability in maven package org.apache.cocoon:cocoon-core
CVE-2018-1000006 Vulnerability in npm package electron
CVE-2020-7760 Vulnerability in maven package org.webjars.bowergithub.components:codemirror
CVE-2019-12043 Vulnerability in maven package org.webjars.bowergithub.jonschlinkert:remarkable
CVE-2022-23913 Vulnerability in maven package org.apache.activemq:artemis-core-client