Description
xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save.
Remediation
References
https://github.com/xuxueli/xxl-job/issues/3333
Related Vulnerabilities
CVE-2020-7630 Vulnerability in npm package git-add-remote
CVE-2023-4853 Vulnerability in maven package io.quarkus:quarkus-csrf-reactive
CVE-2020-7729 Vulnerability in npm package grunt
CVE-2023-45857 Vulnerability in maven package org.webjars.bower:axios
CVE-2020-36518 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind