Command Execution Vulnerability in XXL-JOB 2.2.0 by Xuxueli
CVE-2022-40929

9.8CRITICAL

Key Information:

Vendor

Xuxueli

Status
Vendor
CVE Published:
28 September 2022

What is CVE-2022-40929?

XXL-JOB version 2.2.0 contains a command execution vulnerability within its background tasks feature. This vulnerability arises from the system's ability to execute arbitrary Bash scripts on behalf of users, which has sparked debate over its intended functionality versus potential security risks. Users of XXL-JOB should be cautious, as this flaw could lead to unauthorized actions if misused.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.