Information Disclosure Vulnerability in xxljob by xxl-job
CVE-2020-23811

7.5HIGH

Key Information:

Vendor

Xuxueli

Status
Vendor
CVE Published:
3 September 2020

What is CVE-2020-23811?

The xxljob version 2.2.0 contains a vulnerability that permits the unauthorized disclosure of sensitive user information, including usernames, passwords, and model data. This flaw exists due to inadequate protection in the UserController component, potentially allowing malicious actors to gain access to valuable insights about the user and system configuration.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.