Command Execution Vulnerability in XXL-JOB 2.2.0 by Xuxueli
CVE-2022-40929
9.8CRITICAL
What is CVE-2022-40929?
XXL-JOB version 2.2.0 contains a command execution vulnerability within its background tasks feature. This vulnerability arises from the system's ability to execute arbitrary Bash scripts on behalf of users, which has sparked debate over its intended functionality versus potential security risks. Users of XXL-JOB should be cautious, as this flaw could lead to unauthorized actions if misused.